packetstormsecurity.com
http://packetstormsecurity.com/files/163225/Websvn-2.6.0-Remote-Code-Execution.html CVE-2021-32305
CRITICALNuclei
websvn websvn Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2021-32305 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.
Description
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
websvnBrowse websvn / websvn | VulnCheck | Version data not supplied | |
Proofs of concept
2Catalogued exploits
ExploitDBWebsvn 2.6.0 - Remote Code Execution (Unauthenticated)ExploitDB exploitby g0ldm45kNot analyzed1 file
Repository PoCs
GitHubFredBrave/CVE-2021-32305-websvn-2.6.0Repository PoCby FredBraveStars: 1Not analyzed2 files
Nuclei templates
1ProjectDiscoveryCRITICALWebsvn <2.6.1 - Remote Code ExecutionCVSS 9.8
WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.
Impact
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.
Remediation
Upgrade Websvn to version 2.6.1 or later to mitigate this vulnerability.
WeaknessesCWE-78
Authorsgy741
Template tagscvecve2021websvnrceoastpacketstormvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:websvn:websvn:*:*:*:*:*:*:*:*
https://packetstormsecurity.com/files/163225/Websvn-2.6.0-Remote-Code-Execution.html https://github.com/websvnphp/websvn/pull/142 http://packetstormsecurity.com/files/163225/Websvn-2.6.0-Remote-Code-Execution.html https://nvd.nist.gov/vuln/detail/CVE-2021-32305 https://github.com/HimmelAward/Goby_POC
Source: ProjectDiscovery
References
3github.com
https://github.com/websvnphp/websvn/pull/142 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-32305