CVE-2018-5702
HIGHTransmission < 2.92 - Unauthenticated Remote Code Execution via DNS Rebinding
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-5702. PoCs published by Google Security Research.
AI-analyzed exploit summary This writeup describes a DNS rebinding attack against Transmission BitTorrent client's RPC interface, allowing remote attackers to bypass the localhost restriction and execute arbitrary commands by manipulating the 'download-dir' or 'script-torrent-done-enabled' settings.
Description
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack.
Exploits (1)
This writeup describes a DNS rebinding attack against Transmission BitTorrent client's RPC interface, allowing remote attackers to bypass the localhost restriction and execute arbitrary commands by manipulating the 'download-dir' or 'script-torrent-done-enabled' settings.
References (7)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H