hi,
Multiple vulnerabilities were discovered in the latest version of OpenFiler
appliance, 2.99.1 as reported
here<https://forums.openfiler.com/index.php?/topic/6720-arbitrary-code-execution-stored-xss-vulnerability-in-openfiler-latest-version-2991/>,
here <http://www.exploit-db.com/exploits/33247> and
here<http://www.exploit-db.com/exploits/33248>
OpenFiler is a FreeNAS appliance equivalent.
Vulnerability 1
OpenFiler is vulnerable to an arbitrary code execution attack by not
validating the hostname input, this vulnerability allows an attacker to
execute any system shell command with the root user privileges.
Proof of concept:
i. Login with any available user
ii. Change the hostname value to `cat /etc/passwd`
iii. Submit
Proof of concept vids
Can CVEs please be assigned to these issues?
Tx