exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Serv-U FTP Server 15.1.7 CSV Injection

Serv-U FTP Server 15.1.7 CSV Injection
Posted Dec 16, 2019
Authored by Richard Tan

Serv-U FTP Server version 15.1.7 suffers from a CSV injection vulnerability.

tags | exploit
advisories | CVE-2019-13181
SHA-256 | 2d9ca89fe40ce6f05d287502313bd8a4463446e615ffabcaddff1171deaa2c48

Serv-U FTP Server 15.1.7 CSV Injection

Change Mirror Download
Issue:                  CSV injection vulnerability

CVE: CVE-2019-13181

Security researcher: Richard Tan @ The Missing Link Security

Product name: Serv-U FTP Server

Product version: Tested on 15.1.7

Fixed in: Serv-U 15.1.7 Hotfix 2





# Overview

The application allowed table entries to contain a string which could be
evaluated by Excel as a Dynamic Data Exchange (DDE) macro.

Privileged users who has the appropriate rights to modify or create users
could insert values into user properties which is evaluated as macros if the
user list is exported as an Excel format.



Steps to reproduce (Proof of concept):

1) Login as a user that has privileges to create or modify users.

2) Create a new user and add the following payload into the
"description" field. "=cmd|'/C calc.exe'!A0"

3) Export the user list with a file name "CSVinjection.csv" on the
application server.

4) On the application server, locate the file and execute it. Notice
that a warning sign could be prompted depending the Excel's security
settings. (If so click enable)

5) Observe that the calculator tool is executed. This is a proof of
concept however an adversary could exploit this weakness to potentially gain
access to the application server (or from where ever the file is executed
from).



Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    33 Files
  • 16
    Aug 16th
    23 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    43 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close