vendor:
ClipBucket
by:
Ahmad Ramadhan Amizudin, Wan Ikram, Fikri Fadzil, Jasveer Singh, SEC Consult Vulnerability Lab
CVSS
CRITICAL
OS command injection, arbitrary file upload & SQL injection
-
CWE
Product Name: ClipBucket
Affected Version From: <4.0.0 - Release 4902
Affected Version To: 4.0.0 - Release 4902
Patch Exists: YES
Related CWE: -
CPE: -
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2017
OS command injection, arbitrary file upload & SQL injection
By exploiting the vulnerabilities documented in this advisory, an attacker can fully compromise the web server which has ClipBucket installed. Potentially sensitive data might get exposed through this attack.
Mitigation:
Users are advised to upgrade to the latest version of ClipBucket.