Main
Vulnerability Database
Exploits
ID:6326 - Exploit for Command injection in Xplico - CVE-2017-16666
ID:6326 - Exploit for Command injection in Xplico - CVE-2017-16666
Published: June 17, 2021
Vulnerability identifier: #VU10154
Vulnerability risk: High
CVE-ID: CVE-2017-16666
CWE-ID: CWE-77
Exploitation vector: Remote access
Vulnerable software:
Xplico
Xplico
Link to public exploit:
Vulnerability description
The vulnerability allows a remote authenticated attacker to execute arbitrary commands on the targeted system.
The weakness exists due to improper security restrictions imposed by the affected software. A remote attacker can submit a specially crafted packet capture (PCAP) file, inject and execute arbitrary commands with root privileges.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists due to improper security restrictions imposed by the affected software. A remote attacker can submit a specially crafted packet capture (PCAP) file, inject and execute arbitrary commands with root privileges.
Successful exploitation of the vulnerability may result in system compromise.
Remediation
Update to version 1.2.1.