vendor:
DreamLog
by:
Dj7xpl
7.5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: DreamLog
Affected Version From: DreamLog v0.5
Affected Version To: DreamLog v0.5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
DreamLog v0.5 Remote Exploit
This exploit allows an attacker to execute arbitrary code on a target system running DreamLog v0.5. The vulnerability exists in the 'File' parameter of the script, which can be exploited to upload a malicious file. The exploit takes advantage of a lack of input validation and file upload restrictions.
Mitigation:
To mitigate this vulnerability, it is recommended to update to a patched version of DreamLog or apply any available security patches. Additionally, file upload functionality should be properly validated and restricted to prevent the upload of malicious files.