CVE-2015-6498

Posted by csirt on Nov 02

###################################################################################
#
# SWISSCOM CSIRT ADVISORY – https://www.swisscom.ch/en/about/sustainability/digital-
#switzerland/security.html
#
##################################################################################
#
# CVE ID: CVE-2015-6498
# Product: Home Device Manager
# Vendor: Alcatel-Lucent
# Subject: Code vulnerability, remotely exploitable
# Finder: Dr. Ulrich…

Unauthenticated remote command execution on Cisco Linksys x2000 routers

Posted by Lorenzo Pistone on Nov 02

Hello,
I have found on my router, a Linksys X2000, that there is a poor
validation of the IP target in the ping diagnostics web page
(http://$router_ip/Diagnostics.asp). This can be used to execute
arbitrary commands as the root user on the device. It appears that there
is no need for authentication to exploit the flaw, so this is
exploitable from WAN if the administrator has activated remote
management from the web UI.

The web interface…

DSA-3391 php-horde – security update

It was discovered that the web-based administration interface in the
Horde Application Framework did not guard against Cross-Site Request
Forgery (CSRF) attacks. As a result, other, malicious web pages could
cause Horde applications to perform actions as the Horde user.

CVE-2015-1775

Server-side request forgery (SSRF) vulnerability in the proxy endpoint (api/v1/proxy) in Apache Ambari before 2.1.0 allows remote authenticated users to conduct port scans and access unsecured services via a crafted REST call.

CVE-2015-3186

Cross-site scripting (XSS) vulnerability in Apache Ambari before 2.1.0 allows remote authenticated cluster operator users to inject arbitrary web script or HTML via the note field in a configuration change.

CVE-2015-3270

Apache Ambari before 2.0.2 or 2.1.x before 2.1.1 allows remote authenticated users to gain administrative privileges via unspecified vectors, possibly related to changing passwords.