github.com
https://github.com/JPCERTCC/LogonTracer/releases/tag/v1.2.1 CVE-2018-16167
CRITICALNuclei
jpcert logontracer Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2018-16167 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.
Description
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Description source: CVE List
Exploitation context
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
| CVE List | 1.2.0 and earlier | affected | |
logontracerBrowse jpcert / logontracer | VulnCheck | Version data not supplied | |
Proofs of concept
2Catalogued exploits
ExploitDBLogonTracer 1.2.0 - Remote Code Execution (Unauthenticated)ExploitDB exploitby g0ldm45kNot analyzed1 file
Repository PoCs
GitHubdnr6419/CVE-2018-16167Repository PoCby dnr6419Stars: 0Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALLogonTracer <=1.2.0 - Remote Command InjectionCVSS 9.8
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Impact
Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the target system.
Remediation
Upgrade LogonTracer to a version higher than 1.2.0.
WeaknessesCWE-78
Authorsgy741
Template tagscvecve2018rceoastedblogontracerintrusivejpcertvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:jpcert:logontracer:*:*:*:*:*:*:*:*
https://www.exploit-db.com/exploits/49918 https://nvd.nist.gov/vuln/detail/CVE-2018-16167 https://jvn.jp/en/vu/JVNVU98026636/index.html https://github.com/JPCERTCC/LogonTracer/releases/tag/v1.2.1 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3jvn.jp
https://jvn.jp/en/vu/JVNVU98026636/index.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-16167