vendor:
SAS Hotel Management System
by:
ZoRLu
8.8
CVSS
HIGH
Remote Shell Upload
434
CWE
Product Name: SAS Hotel Management System
Affected Version From: Prior to 1.0.1
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009
SAS Hotel Management System Remote Shell Upload
A vulnerability in the SAS Hotel Management System allows an attacker to upload a malicious shell to the server. The attacker can register an account on the website and upload a malicious shell as a profile picture. The malicious shell can then be accessed at the upload_images directory. This vulnerability affects versions prior to 1.0.1.
Mitigation:
Upgrade to version 1.0.1 or later.