Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-1000226 PoC — Cobbler 访问控制错误漏洞

Source
Associated Vulnerability
Title:Cobbler 访问控制错误漏洞 (CVE-2018-1000226)
Description:Cobbler是一款网络安装服务器套件,它能够快速建立Linux网络安装环境。 Cobbler 2.0.0+及之前版本中的XMLRPC API(/cobbler-api)存在访问控制错误漏洞,该漏洞源于程序没有正确的验证API端点内的安全令牌。攻击者可利用该漏洞提升权限,操纵或泄露数据,获取LDAP凭证。
Description
Cobbler versions 2.6.11+, but code inspection suggests at least 2.0.0+ and possibly even older versions, may be vulnerable to an authentication bypass vulnerability in XMLRPC API (/cobbler_api) that can result in privilege escalation, data manipulation or exfiltration, and LDAP credential harvesting. This attack appear to be exploitable via "network connectivity". Taking advantage of improper validation of security tokens in API endpoints. Please note this is a different issue than CVE-2018-10931.
File Snapshot

id: CVE-2018-1000226 info: name: Cobbler - Authentication Bypass author: c-sh0 severity: crit ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.