accept no compromises
Showing 1 - 1 of 1 RSS Feed

Files

RedHat Piranha Virtual Server Package passwd.php3 Arbitrary Command Execution
Posted Feb 15, 2010
Authored by patrick | Site metasploit.com

This Metasploit module abuses two flaws - a meta-character injection vulnerability in the HTTP management server of RedHat 6.2 systems running the Piranha LVS cluster service and GUI (rpm packages: piranha and piranha-gui). The vulnerability allows an authenticated attacker to execute arbitrary commands as the Apache user account (nobody) within the /piranha/secure/passwd.php3 script. The package installs with a default user and password of piranha:q which was exploited in the wild.

tags | exploit, web, arbitrary
systems | linux, redhat
advisories | CVE-2000-0322, CVE-2000-0248
MD5 | f67f90a640b118d5d59f7d2fd5dcfd0e
Page 1 of 1
Back1Next

Top Authors In Last 30 Days

packet storm

© 2012 Packet Storm. All rights reserved.

close