vendor:
QiHang Media Web Digital Signage
by:
LiquidWorm
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: QiHang Media Web Digital Signage
Affected Version From: 3.0.9.0
Affected Version To: 3.0.9.0
Patch Exists: NO
Related CWE:
CPE: a:shenzhen_xingmeng_qihang_media:web_digital_signage:3.0.9.0
Platforms Tested: Microsoft Windows Server 2012 R2 Datacenter
2020
QiHang Media Web Digital Signage 3.0.9 – Remote Code Execution (Unauthenticated)
The application suffers from an unauthenticated remote code execution. The vulnerability is caused due to lack of verification when uploading files with QH.aspx that can be written in any location by utilizing the 'remotePath' parameter to traverse through directories. Abusing the upload action and the 'fileToUpload' parameter, an unauthenticated attacker can exploit this to execute system commands by uploading a malicious ASPX script.
Mitigation:
Apply the vendor patch or update to a newer version of the software.