GestioIP Remote Code Execution Vulnerability
Vulnerability
A remote code execution vulnerability exists in GestioIP version 3.5.7. The issue arises from the file upload functionality, which allows an authenticated attacker to upload a malicious file named 'perlcmd.cgi'. This file overwrites the existing 'upload.cgi' file, thereby enabling the execution of arbitrary commands on the server.
Impact
Exploitation of this vulnerability allows for authenticated remote code execution on the server where GestioIP is installed.
Reproduction
To reproduce this vulnerability, first log into the GestioIP application with valid credentials. Then, upload a file named 'perlcmd.cgi' through the application's file upload feature, ensuring that it is saved as 'upload.cgi' on the server. This can be done using a 'curl' command that specifies the file to be uploaded and the target filename. Once the backdoor is uploaded, it can be accessed via a web browser or 'curl' command, executing any commands on the server and returning the output.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
