CVE-2008-6539
DeStar 0.2.2-5 - Authenticated Static Code Injection via Pin Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2008-6539. PoCs published by nonroot.
AI-analyzed exploit summary This exploit targets a command injection vulnerability in destar 0.2.2-5 by injecting malicious configuration commands via URL-encoded parameters. It first authenticates with valid credentials, then sends a payload to create a new privileged user and SIP phone configuration, and finally verifies the exploit by logging in as the newly created user.
Description
Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitrary administrators and inject arbitrary Python code into destar_cfg.py via a crafted pin parameter.
Exploits (1)
This exploit targets a command injection vulnerability in destar 0.2.2-5 by injecting malicious configuration commands via URL-encoded parameters. It first authenticates with valid credentials, then sends a payload to create a new privileged user and SIP phone configuration, and finally verifies the exploit by logging in as the newly created user.