endian_firewall_authenticated_rce CVE-2021-27201

Endinan Firewall Community version 3.3.2 authenticated remote code execution as nobody.

when i was start create backup, output of ps command is be interesting.

dikkatcekennokta

and checking the input is validated ?

create-file

no. we can run command.check the permission.

permission

we can run command as nobody.

1-) login in web application.

2-) create backup and select any options and write payload to comment. eg. aaaa$(id)bbbb

3-) start to backup.

                                               Proof Of Concept

endian_poc

POC VIDEO

proof of concept as video: watch