CVE-2018-7739
critical · 9.8antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and password parameters, as demonstrated by a username=>&password=%0a string to the /login URI. This allows obtaining root permissions within the web management console, because the login process uses Java's ProcessBuilder class and a bash script called antsle-auth with insufficient input validation.
9.8
CVSS
53.2%
EPSS (exploit prob.)
99th
EPSS percentile
2018-03-07
Published
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| antsle | antman | <= 0.9.0c |
Check a specific version with /api/v1/cve/match.
References
- http://blog.codecatoctin.com/2018/02/antman-authentication-bypass.html
- https://www.exploit-db.com/exploits/44220/
- https://www.exploit-db.com/exploits/44262/
- http://blog.codecatoctin.com/2018/02/antman-authentication-bypass.html
- https://www.exploit-db.com/exploits/44220/
- https://www.exploit-db.com/exploits/44262/
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-7739