Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2017-14135 PoC — opendreambox 操作系统命令注入漏洞

Source
Associated Vulnerability
Title:opendreambox 操作系统命令注入漏洞 (CVE-2017-14135)
Description:opendreambox是一套嵌入式Linux系统的构建框架。webadmin plugin是其中的一个Web管理插件。 opendreambox 2.0.0版本中的webadmin插件的enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py文件存在安全漏洞。远程攻击者可通过向/script URL发送带有shell元字符的‘command’参数利用该漏洞执行任意的操作系统命令。
Description
OpenDreambox 2.0.0 is susceptible to remote code execution via the webadmin plugin. Remote attackers can execute arbitrary OS commands via shell metacharacters in the command parameter to the /script URI in enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py.
File Snapshot

id: CVE-2017-14135 info: name: OpenDreambox 2.0.0 - Remote Code Execution author: alph4byt3 s ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.