Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CLOSED] Arbitrary file removal in add local applications form ‘uuid’ parameter (High) #331

Closed
oti-tech opened this issue Jun 18, 2014 · 0 comments

Comments

@oti-tech
Copy link

Issue by areynold
Monday Sep 09, 2013 at 15:46 GMT
Originally opened as https://github.com/opentechinstitute/luci-commotion-apps/issues/13


In the same code snippet as described in #11, arbitrary file
removal is possible:

https://github.com/opentechinstitute/commotion-apps/blob/3bcf912eec5d3b7b0192cf4c21e334c6775ec482/lua/luci/controller/commotion/apps_controller.lua#L534-L543

To exploit this vulnerability, attacker should set up a new application (unique name, ip address/port pair) and perform path traversal in uuid parameter to remove arbitrary file.

Originally reported as WRT-01-008

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants