20180501 SSRF(Server Side Request Forgery) in Cockpit 0.4.4-0.5.5 (CVE-2018-9302)mailing list
http://seclists.org/fulldisclosure/2018/May/10 CVE-2018-9302
CRITICAL
Cockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery
Record summary
CVE-2018-9302 has a selected CVSS score of 9.1 (critical); EIP currently links 1 catalogued exploit.
Description
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14611, which was about version 0.13.0, which (surprisingly) is an earlier version than 0.4.4.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCockpit CMS 0.4.4 < 0.5.5 - Server-Side Request ForgeryExploitDB exploitby Qian Wu_ Bo Wang_ Jiawang ZhangNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-9302 44567exploit
https://www.exploit-db.com/exploits/44567