Full Disclosure mailing list archives

SolusVM WHMCS module privilege escalation, also libcurl vuln?


From: Sven Slootweg <admin () cryto net>
Date: Sun, 23 Jun 2013 22:07:57 +0002

Ran across a new post on a blog I frequently visit: http://localhost.re/p/solusvm-whmcs-module-316-vulnerability

It describes a privilege escalation vulnerability in the WHMCS module for SolusVM that basically lets you do anything, but if I'm reading it correctly, it appears to be a result of a vulnerability - or at the very least weakness - in the implementation of libcurl; in particular, weak randomness in generating the form boundary.

Thoughts?

Note: I'm not the author of this exploit (it's actually quite a bit beyond my capabilities), I just ran across it and decided to post here since it doesn't seem to be discussed anywhere. Just to avoid people making incorrect assumptions... again :)

- Sven Slootweg
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: