vendor:
MiwoFTP
by:
Gjoko 'LiquidWorm' Krstic
8.8
CVSS
HIGH
Cross-Site Request Forgery Remote Code Execution
352
CWE
Product Name: MiwoFTP
Affected Version From: 1.0.5
Affected Version To: 1.0.5
Patch Exists: YES
Related CWE: N/A
CPE: a:miwisoft:miwoftp
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache 2.4.10 (Win32), PHP 5.6.3, MySQL 5.6.21
2015
WordPress MiwoFTP Plugin 1.0.5 CSRF Arbitrary File Creation Exploit (RCE)
MiwoFTP WP Plugin suffers from a cross-site request forgery remote code execution vulnerability. The application allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions like executing arbitrary PHP code by uploading a malicious PHP script file, with administrative privileges, if a logged-in user visits a malicious web site.
Mitigation:
Ensure that all requests are validated before performing any action.