Xplico before 1.2.1 allows remote authenticated users to execute arbitrary...
Vulnerability Description
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name of an uploaded PCAP file. NOTE: this issue can be exploited without authentication by leveraging the user registration feature.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-16666
Credits & Attribution
No credits recorded in the NVD database.
References
- http://packetstormsecurity.com/files/145639/Xplico-Remote-Code-Execution.html
- http://blog.securityonion.net/2017/11/security-advisory-for-xplico-120.html
- https://www.xplico.org/archives/1538
- https://pentest.blog/advisory-xplico-unauthenticated-remote-code-execution-cve-2017-16666/
- https://www.exploit-db.com/exploits/43430/
- http://www.rapid7.com/db/modules/exploit/linux/http/xplico_exec
Affected Vendor
xplico
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.