vendor:
Wp2Fac
by:
Ahmet Ümit BAYRAM
7.5
CVSS
HIGH
OS Command Injection
78
CWE
Product Name: Wp2Fac
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:metinyesil:wp2fac:1.0
Platforms Tested: Kali Linux, Windows 11
2023
Wp2Fac v1.0 – OS Command Injection
This exploit allows an attacker to execute arbitrary operating system commands on the target system by injecting malicious commands through the 'numara' parameter in the 'send.php' endpoint.
Mitigation:
To mitigate this vulnerability, it is recommended to sanitize and validate user input before using it in command execution.