CVE-2007-3010
CRITICAL KEV NUCLEIAlcatel OmniPCX Enterprise < 7.1 - Remote Command Execution via Unified Maintenance Tool
Title source: llmExploitation Summary
CVE-2007-3010 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added April 15, 2022.
EIP tracks 4 public exploits from researchers including Metasploit, patrick, RedTeam Pentesting GmbH, including a Metasploit module exploits/linux/http/alcatel_omnipcx_mastercgi_exec.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in Alcatel-Lucent OmniPCX Enterprise's masterCGI via shell metacharacters in the 'user' parameter of the 'ping' action. It sends a crafted HTTP GET request to execute arbitrary commands as the 'httpd' user.
Description
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
Exploits (4)
This Metasploit module exploits a command injection vulnerability in Alcatel-Lucent OmniPCX Enterprise's masterCGI via shell metacharacters in the 'user' parameter of the 'ping' action. It sends a crafted HTTP GET request to execute arbitrary commands as the 'httpd' user.
This Metasploit module exploits a command injection vulnerability in Alcatel-Lucent OmniPCX Enterprise's masterCGI binary via the 'user' parameter in the 'ping' action. It sends a crafted HTTP GET request to execute arbitrary commands as the 'httpd' user.
This exploit leverages a command injection vulnerability in Alcatel-Lucent OmniPCX Enterprise by injecting arbitrary commands via the 'user' parameter in the 'masterCGI' endpoint. The provided curl command demonstrates executing 'ls -l' on the target system.
This Metasploit module exploits a command injection vulnerability in Alcatel-Lucent OmniPCX Enterprise's masterCGI via shell metacharacter injection in the 'user' parameter of the 'ping' action. It executes arbitrary commands as the 'httpd' user but is limited to command-line payloads due to process termination post-response.
Nuclei Templates (1)
title:"OmniPCX for Enterprise" || http.title:"omnipcx for enterprise"
app="Alcatel_Lucent-OmniPCX-Enterprise" || app="alcatel_lucent-omnipcx-enterprise" || title="omnipcx for enterprise"
References (10)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H