A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://documentation.solarwinds.com/en/success_center/servu/Content/Release_Notes/Servu_15-1-7_release_notes.htm | release notes vendor advisory |
https://support.solarwinds.com/SuccessCenter/s/article/Serv-U-Potential-elevation-of-privileges-on-Linux-systems | vendor advisory |
http://packetstormsecurity.com/files/153333/Serv-U-FTP-Server-15.1.6-Privilege-Escalation.html | exploit vdb entry third party advisory |
https://blog.vastart.dev/2019/06/cve-2019-12181-serv-u-exploit-writeup.html | broken link |
http://packetstormsecurity.com/files/153505/Serv-U-FTP-Server-prepareinstallation-Privilege-Escalation.html | exploit vdb entry third party advisory |