Vulnerabilities > CVE-2018-9302 - Server-Side Request Forgery (SSRF) vulnerability in Getcockpit Cockpit

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
getcockpit
CWE-918
critical
exploit available

Summary

SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14611, which was about version 0.13.0, which (surprisingly) is an earlier version than 0.4.4.

Vulnerable Configurations

Part Description Count
Application
Getcockpit
1

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionCockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery. CVE-2018-9302. Webapps exploit for PHP platform. Tags: Server-Side Request Forgery (SSRF)
fileexploits/php/webapps/44567.txt
idEDB-ID:44567
last seen2018-05-24
modified2018-05-02
platformphp
port80
published2018-05-02
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/44567/
titleCockpit CMS 0.4.4 < 0.5.5 - Server-Side Request Forgery
typewebapps

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/147412/cockpitcms055-ssrf.txt
idPACKETSTORM:147412
last seen2018-05-07
published2018-04-28
reporterJiawang Zhang
sourcehttps://packetstormsecurity.com/files/147412/Cockpit-CMS-0.5.5-Server-Side-Request-Forgery.html
titleCockpit CMS 0.5.5 Server-Side Request Forgery