header-logo
Suggest Exploit
vendor:
Asset Manager CMS and File Editor
by:
Shichemt Alen & NeT_Own3r [ Meher Assel ]
7,5
CVSS
HIGH
Shell Upload Vulnerability
434
CWE
Product Name: Asset Manager CMS and File Editor
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: a:asset_manager:asset_manager_cms_and_file_editor
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

Asset Manager ( Shell Upload Vulnerability )

Asset Manager is vulnerable to shell upload vulnerability. An attacker can upload a malicious shell file with the extension .php or .asp to the web server. For ASP shell File name can be like this : xxx.asp;xx.jpg

Mitigation:

Restrict the file types that can be uploaded to the web server. Validate the file type before uploading it to the server.
Source

Exploit-DB raw data:

# Title: Asset Manager ( Shell Upload Vulnerability )
# Version: 1.0
# Author: Shichemt Alen & NeT_Own3r [ Meher Assel ]
# Software Link: http://www.sourcecodeonline.com/details/asset_manager_cms_and_file_editor.html
# Price : $35.00

############### Founded By Net_Own3r & Shichemt Alen ###############

Hi All Muslims Brothers & All Hackers


# Exploit :

http://127.0.0.1/assetmanager/assetmanager.php (Upload shell php)
or
http://127.0.0.1/assetmanager/assetmanager.asp (Upload shell asp)

# Note :
For ASP shell File name can be like this : xxx.asp;xx.jpg <=== No more priv8 ;)

####################################################################

MaiL :
Meher Assel : ow3ner@hotmail.com<mailto:ow3ner@hotmail.com>
Shichemt Alen : Shichemt@hotmail.com<mailto:Shichemt@hotmail.com>

###################### Made In Tunisia [+216] ###########################