vendor:
phpMyBackupPro
by:
hyp3rlinx
7.5
CVSS
HIGH
Remote Command Execution / CSRF
CWE
Product Name: phpMyBackupPro
Affected Version From: 2.5
Affected Version To: 2.5
Patch Exists: NO
Related CWE:
CPE: phpmybackuppro:v2.5
Platforms Tested:
Remote Command Execution in phpMyBackupPro v.2.5 (PMBP)
phpMyBackupPro v.2.5 (PMBP) allows a malicious user to inject persistent arbitrary PHP/OS commands into the configuration file, leading to remote command execution. This can be achieved through a CSRF driveby or by a local malicious user in a shared host environment. The payload leverages the backtick operator to execute OS commands on the victim's system.
Mitigation:
It is recommended to upgrade to the latest version of phpMyBackupPro to mitigate this vulnerability. Additionally, users should be cautious when visiting malicious webpages or clicking infected links.