vendor:
Lunar CMS
by:
Gjoko 'LiquidWorm' Krstic
9,3
CVSS
HIGH
Unauthenticated Remote Command Execution
78
CWE
Product Name: Lunar CMS
Affected Version From: 3.3
Affected Version To: 3.3
Patch Exists: YES
Related CWE: N/A
CPE: a:lunarcms:lunar_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Apache/2.4.7 (Win32), PHP/5.5.6, MySQL 5.6.14
2014
Lunar CMS 3.3 Unauthenticated Remote Command Execution Exploit
Lunar CMS suffers from an unauthenticated arbitrary command execution vulnerability. The issue is caused due to the improper verification of elfinder's upload/create/rename function in the file manager. This can be exploited to execute arbitrary PHP code by creating or uploading a malicious PHP script file that will be stored in '/files' directory.
Mitigation:
Vendor fix: http://lunarcms.com/Get.html