CVE-2017-17560

An issue was discovered on Western Digital MyCloud PR4100 2.30.172 devices. The web administration component, /web/jquery/uploader/multi_uploadify.php, provides multipart upload functionality that is accessible without authentication and can be used to place a file anywhere on the device's file system. This allows an attacker the ability to upload a PHP shell onto the device and obtain arbitrary code execution as root.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:westerndigital:my_cloud_pr4100_firmware:2.30.172:*:*:*:*:*:*:*
cpe:2.3:h:westerndigital:my_cloud_pr4100:-:*:*:*:*:*:*:*

History

21 Nov 2024, 03:18

Type Values Removed Values Added
References () https://download.exploitee.rs/file/generic/Exploiteers-DEFCON25.pdf - Exploit, Third Party Advisory () https://download.exploitee.rs/file/generic/Exploiteers-DEFCON25.pdf - Exploit, Third Party Advisory
References () https://github.com/rapid7/metasploit-framework/pull/9248 - Third Party Advisory () https://github.com/rapid7/metasploit-framework/pull/9248 - Third Party Advisory
References () https://www.exploit-db.com/exploits/43356/ - Exploit, Third Party Advisory, VDB Entry () https://www.exploit-db.com/exploits/43356/ - Exploit, Third Party Advisory, VDB Entry

Information

Published : 2017-12-12 18:29

Updated : 2024-11-21 03:18


NVD link : CVE-2017-17560

Mitre link : CVE-2017-17560

CVE.ORG link : CVE-2017-17560


JSON object : View

Products Affected

westerndigital

  • my_cloud_pr4100
  • my_cloud_pr4100_firmware
CWE
CWE-287

Improper Authentication