CVE-2014-8684
CRITICALCodeIgniter <3.0 & Kohana 3.2.3-3.3.2 - Code Injection
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2014-8684.
Includes Metasploit module exploits/linux/http/seagate_nas_php_exec_noauth.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated remote command execution vulnerability in Seagate Business NAS devices via a local file inclusion flaw in the CodeIgniter session cookie's language parameter. It decrypts the session cookie, modifies it to gain admin privileges, and injects a PHP payload to achieve RCE.
Description
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof session cookies and consequently conduct PHP object injection attacks by leveraging use of standard string comparison operators to compare cryptographic hashes.
Exploits (2)
This Metasploit module exploits an unauthenticated remote command execution vulnerability in Seagate Business NAS devices via a local file inclusion flaw in the CodeIgniter session cookie's language parameter. It decrypts the session cookie, modifies it to gain admin privileges, and injects a PHP payload to achieve RCE.
This Metasploit module exploits an unauthenticated remote command execution vulnerability in Seagate Business NAS devices via a local file inclusion flaw in the CodeIgniter session cookie's language parameter. It decrypts the session cookie, modifies it to gain admin privileges, and uploads a PHP payload to achieve RCE.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H