logo

Full Disclosure: Authenticated Command Execution…

ID: a09b4018-c3fa-5355-a4c4-c983540bd31e

STIX ID: report--a09b4018-c3fa-5355-a4c4-c983540bd31e

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

On 2016-05-19 TrustedSec discovered an authenticated command injection vulnerability in pfSense's WebGUI (auth.inc via system_groupmanager.php, "members" parameter) allowing an authenticated user with access to the Groups page to execute commands as root. The issue was responsibly disclosed to pfSense on 2016-06-08 and promptly fixed; a simple proof-of-concept (`'`whoami>/usr/local/www/whoami.txt`'`) and later public write-ups and an Exploit-DB entry document exploitation details and a CTF use-case.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.