header-logo
Suggest Exploit
vendor:
Lan.FS Messenger
by:
Benjamin Kunz Mejri
8,2
CVSS
CRITICAL
Command Execution
78
CWE
Product Name: Lan.FS Messenger
Affected Version From: LAN.FS Messenger v2.4
Affected Version To: LAN.FS Messenger v2.4
Patch Exists: YES
Related CWE: N/A
CPE: a:lan.fs:lan.fs_messenger
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 2000/XP/2003/Vista & Windows 7
2012

LAN.FS Messenger v2.4 – Command Execution Vulnerability

A command execution vulnerability is detected in the official LAN.FS v2.4 Messenger Software. The vuln allows remote attackers to execute system specific commands with system privileges. The vulnerability is located in the `message` value of the `send` POST method request. Remote attackers are able to inject own malicious commands to compromise the system.

Mitigation:

The vulnerability can be patched by a secure parse and encode of the POST method request values.
Source

Exploit-DB raw data: