vendor:
Continuum
by:
David Shanahan, wvu
N/A
CVSS
N/A
Command Injection
78
CWE
Product Name: Continuum
Affected Version From: Apache Continuum <= 1.4.2
Affected Version To: Apache Continuum <= 1.4.2
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Windows, Mac
2016
Apache Continuum Arbitrary Command Execution
This module exploits a command injection in Apache Continuum <= 1.4.2. By injecting a command into the installation.varValue POST parameter to /continuum/saveInstallation.action, a shell can be spawned.
Mitigation:
Upgrade to Apache Continuum version 1.4.3 or later