Tag
#csrf
This Metasploit module exploits an authenticated file upload vulnerability in Subrion CMS versions 4.2.1 and lower. The vulnerability is caused by the .htaccess file not preventing the execution of .pht, .phar, and .xhtml files. Files with these extensions are not included in the .htaccess blacklist, hence these files can be uploaded and executed to achieve remote code execution. In this module, a .phar file with a randomized name is uploaded and executed to receive a Meterpreter session on the target, then deletes itself afterwards.
COURIER DEPRIXA version 2.5 suffers from a cross site request forgery vulnerability.
WebCalendar version 1.3 suffers from a cross site request forgery vulnerability.
An issue in Eramba Limited Eramba Enterprise v.3.19.1 allows a remote attacker to execute arbitrary code via the path parameter in the URL.
CRM Education Akademik version 9.0 suffers from a directory traversal vulnerability.
Courier Deprixa Pro Integrated Web System version 3.2.5 suffers from a cross site request forgery vulnerability.
Coupons CMS version 4.00 suffers from an open redirection vulnerability.
Given the privileged position these devices occupy on the networks they serve, they are prime targets for attackers, so their security posture is of paramount importance.
Eramba version 3.19.1 suffers from a remote command execution vulnerability.