CVE-2017-6526
CRITICALdnaTools dnaLIMS 4-2015s13 - Unauthenticated Remote Code Execution via sysAdmin.cgi
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-6526.
PoCs published by Shorebreak Security, h00die <[email protected]>, flakey_biscuit <[email protected]>, including Metasploit module exploits/linux/http/dnalims_admin_exec.
AI-analyzed exploit summary This is a vulnerability advisory detailing multiple issues in dnaLIMS, including session hijacking (CVE-2017-6529), directory traversal, and XSS. No exploit code is provided, only descriptions and technical summaries.
Description
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected administrative web shell (cgi-bin/dna/sysAdmin.cgi POST requests).
Exploits (2)
This is a vulnerability advisory detailing multiple issues in dnaLIMS, including session hijacking (CVE-2017-6529), directory traversal, and XSS. No exploit code is provided, only descriptions and technical summaries.
This Metasploit module exploits an unauthenticated command execution vulnerability in dnaLIMS via the sysAdmin.cgi endpoint. It sends a POST request with a payload to execute arbitrary commands on the target system.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H