TeemIp IPAM Command Injection - LATEST BINDAS NEWS

LATEST BINDAS NEWS

Read latest bindas news per minutes updates check it now per minutes news in all over world

Breaking

Home Top Ad

Post Top Ad

Thursday, 4 April 2019

TeemIp IPAM Command Injection

This Metasploit module exploits a command injection vulnerability in TeemIp versions prior to 2.4.0. The "new_config" parameter of "exec.php" allows you to create a new PHP file with the exception of config information. The malicious PHP code sent is executed instantaneously and is not saved on the server. The vulnerability can be exploited by an authorized user (Administrator). Module allows remote command execution by sending php payload with parameter 'new_config'.

from Files ≈ Packet Storm https://ift.tt/2CRB3Be

No comments:

Post a Comment

Post Bottom Ad

Pages

//]]> }); /*]]>*/