Description
Zenoss Core 3.x contains a command injection vulnerability in the showDaemonXMLConfig endpoint. The daemon parameter is passed directly to a Popen() call in ZenossInfo.py without proper sanitation, allowing authenticated users to execute arbitrary commands on the server as the zenoss user.
Problem types
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
3.0
Credits
bcoles
References
www.exploit-db.com/exploits/20205
raw.githubusercontent.com/...oss_showdaemonxmlconfig_exec.rb
www.exploit-db.com/exploits/37571
web.archive.org/...-3.2.1-multiple-security-vulnerabilities/
sourceforge.net/projects/zenoss/
www.vulncheck.com/advisories/zenoss-command-execution