CVE-2017-5941
CVE-2017-5941
An issue was discovered in the node-serialize package 0.0.4 for Node.js. Untrusted data passed into the unserialize() function can be exploited to achieve arbitrary code execution by passing a JavaScript Object with an Immediately Invoked Function Expression (IIFE).
Productos afectados
n/a · n/aPoCs públicas encontradas — 11
githubgithub.com/uartu0/nodejshell★ 2githubgithub.com/kylew1004/cve-2017-5941-poc-docker-lab★ 0githubgithub.com/f41k0n/RCE-NodeJs★ 0githubgithub.com/Frivolous-scholar/CVE-2017-5941-NodeJS-RCE★ 0githubgithub.com/turnernator1/Node.js-CVE-2017-5941★ 0githubgithub.com/Cr4zyD14m0nd137/Lab-for-cve-2018-15133★ 0exploitdbwww.exploit-db.com/exploits/50036no verificadocve_referencepacketstormsecurity.com/files/163222/Node.JS-Remote-Code-Execution.htmlno verificadoexploitdbwww.exploit-db.com/exploits/45265no verificadoexploitdbwww.exploit-db.com/exploits/49552no verificadocve_referencepacketstormsecurity.com/files/161356/Node.JS-Remote-Code-Execution.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://packetstormsecurity.com/files/161356/Node.JS-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/163222/Node.JS-Remote-Code-Execution.htmlhttps://nodesecurity.io/advisories/311https://opsecx.com/index.php/2017/02/08/exploiting-node-js-deserialization-bug-for-remote-code-execution/http://www.securityfocus.com/bid/96225