.. / CVE-2017-14135

Exploit for OpenDreambox 2.0.0 - Remote Code Execution (CVE-2017-14135)

Description:

OpenDreambox 2.0.0 is susceptible to remote code execution via the webadmin plugin. Remote attackers can execute arbitrary OS commands via shell metacharacters in the command parameter to the /script URI in enigma2-plugins/blob/master/webadmin/src/WebChilds/Script.py.

Nuclei Template

View the template here CVE-2017-14135.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2017/CVE-2017-14135.yaml
Copy

References:

https://nvd.nist.gov/vuln/detail/CVE-2017-14135
https://the-infosec.com/2017/05/12/from-shodan-to-rce-opendreambox-2-0-0-code-execution/
https://github.com/qazbnm456/awesome-cve-poc
https://www.exploit-db.com/exploits/42293
https://the-infosec.com/2017/07/05/from-shodan-to-rce-opendreambox-2-0-0-code-execution/