Files ≈ Packet Storm Packet Storm - Information Security News, Files, Tools, Exploits, Advisories and Whitepapers http://packetstormsecurity.org/ en-us Mon, 28 May 2012 06:56:50 GMT Packet Storm 144400 http://packetstormsecurity.org/ http://www.google-analytics.com/__utm.gif?utmwv=1.3&utmn=1222853685&utmcs=ISO-8859-1&utmsr=31337x31337&utmsc=32-bit&utmul=en-us&utmje=0&utmfl=-&utmcn=1&utmdt=Files%u2248%20Packet%20Storm&utmhn=packetstormsecurity.org&utmr=-&utmp=%2F1002-exploits%2Fpiranha_passwd_exec.rb.txt%2F&utmac=UA-18885198-1&utmcc=__utma%3D32867617.1222853685.1338188210.1338188210.1338188210.1%3B%2B__utmz%3D32867617.1338188210.1.1.utmccn%3D(direct)%7Cutmcsr%3D(direct)%7Cutmcmd%3D(none) RedHat Piranha Virtual Server Package passwd.php3 Arbitrary Command Execution http://packetstormsecurity.org/files/86303/piranha_passwd_exec.rb.txt http://packetstormsecurity.org/files/86303/piranha_passwd_exec.rb.txt http://packetstormsecurity.org/files/86303/RedHat-Piranha-Virtual-Server-Package-passwd.php3-Arbitrary-Command-Execution.html Mon, 15 Feb 2010 22:14:30 GMT This Metasploit module abuses two flaws - a meta-character injection vulnerability in the HTTP management server of RedHat 6.2 systems running the Piranha LVS cluster service and GUI (rpm packages: piranha and piranha-gui). The vulnerability allows an authenticated attacker to execute arbitrary commands as the Apache user account (nobody) within the /piranha/secure/passwd.php3 script. The package installs with a default user and password of piranha:q which was exploited in the wild.