mailing list archives
SolusVM WHMCS module privilege escalation, also libcurl vuln?
From: Sven Slootweg <admin () cryto net>
Date: Sun, 23 Jun 2013 22:07:57 +0002
Ran across a new post on a blog I frequently visit:
It describes a privilege escalation vulnerability in the WHMCS module
for SolusVM that basically lets you do anything, but if I'm reading it
correctly, it appears to be a result of a vulnerability - or at the
very least weakness - in the implementation of libcurl; in particular,
weak randomness in generating the form boundary.
Note: I'm not the author of this exploit (it's actually quite a bit
beyond my capabilities), I just ran across it and decided to post here
since it doesn't seem to be discussed anywhere. Just to avoid people
making incorrect assumptions... again :)
- Sven Slootweg
Full-Disclosure - We believe in it.
Hosted and sponsored by Secunia - http://secunia.com/
- SolusVM WHMCS module privilege escalation, also libcurl vuln? Sven Slootweg (Jun 24)