Serv-U FTP/MFT Server...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

详情来源:https://www.trustwave.com/Resources/SpiderLabs-Blog/Exploiting-Privilege-Escalation-in-Serv-U-by-SolarWinds/?page=1&year=0&month=0 I was recently working on an external network penetration test where I identified a new vulnerability in a file sharing web application called Serv-U by SolarWinds. This vulnerability granted me administrative privileges to the Serv-U application, and, allowed for remote code execution within the context of the SYSTEM user account. In order to demonstrate identification and exploitation of the privilege escalation vulnerability and achieve remote code execution, I will install a trial version of the Serv-U application on a Windows 7 virtual machine. ![1-Install as service](https://images.seebug.org/content/images/2017/04/6a0133f264aa62970b01b7c8ddc3f2970b-800wi.png) Once Serv-U has been installed, no configuration changes are necessary to exploit the vulnerability. Note that by default the Serv-U web server is listening on the loopback interface,...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息