vendor:
KingMedia
by:
Efren Diaz
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: KingMedia
Affected Version From: 1.x
Affected Version To: 4.1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2018
KingMedia 4.1 – Remote Code Execution
This exploit allows an attacker to upload arbitrary files to the KingMedia CMS. By uploading a malicious file, an attacker can execute arbitrary code on the target system.
Mitigation:
Update to a patched version of KingMedia CMS.