vendor:
XpoLog Center
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: XpoLog Center
Affected Version From: 5.4018
Affected Version To: 6.4469
Patch Exists: NO
Related CWE: N/A
CPE: a:xpolog:xpolog_center
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache-Coyote/1.1, Microsoft Windows Server 2012, Microsoft Windows 7 Professional SP1 EN 64bit, Java/1.7.0_45, Java/1.8.0.91
2016
XpoLog Center V6 CSRF Remote Command Execution
XpoLog suffers from arbitrary command execution. Attackers can exploit this issue using the task tool feature and adding a command with respected arguments to given binary for execution. In combination with the CSRF an attacker can execute system commands with SYSTEM privileges.
Mitigation:
Ensure that the application is not vulnerable to CSRF attacks and that the application is not vulnerable to command injection.