Videos

Published on December 21st, 2014 📆 | 2022 Views ⚑

0

IPCop 2.1.2 XSS to CSRF to RCE PoC


tts


A Remote Command Execution is available into theIPCop 2.0.6 to 2.1.2 version. But this RCE is protected from CSRF with the referer checking.
There is an XSS into GET param usable to bypass this CSRF security.
This XSS seems to be only available in IE (because other browsers URLEncode it automatically).
The technic is to exploit the XSS GET to load a third script in the context of IPCop, which perform an AJAX request with the right IPCop referer to the final vulnerable page for remote command execution.
RXSS is now patched in 2.1.3 version and RCE in 2.1.5.


2014-12-21 13:24:16

source





Tagged with:



Comments are closed.