vendor:
1024 CMS
by:
JosS
9.3
CVSS
HIGH
Remote File Inclusion (RFI)
98
CWE
Product Name: 1024 CMS
Affected Version From: 1.4.2004
Affected Version To: 1.4.2004
Patch Exists: YES
Related CWE: N/A
CPE: a:1024cms:1024_cms
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2008
1024 CMS <= 1.4.4 Remote Command Execution with RFI (c99) Exploit
This exploit allows an attacker to execute arbitrary code on a vulnerable system. It is based on a vulnerability in 1024 CMS version 1.4.4, which allows an attacker to inject malicious code into the application via a Remote File Inclusion (RFI) attack. The malicious code is then executed on the vulnerable system.
Mitigation:
To mitigate this vulnerability, administrators should ensure that the application is running the latest version of 1024 CMS and that all security patches are applied. Additionally, administrators should ensure that the application is configured to use secure authentication methods and that all user input is properly sanitized.