vendor:
Agoko CMS
by:
staker
7.5
CVSS
HIGH
Remote Command Execution
CWE
Product Name: Agoko CMS
Affected Version From: 0.4
Affected Version To: 0.4
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
Agoko CMS Remote Commands Execution Exploit
This exploit allows an attacker to execute remote commands on a target system running Agoko CMS version 0.4 or earlier. The attacker needs to provide the host and path as input parameters to the exploit script. The script checks if a shell already exists on the target system and if not, proceeds to inject a shell. Once the shell is injected, the attacker can execute arbitrary commands on the target system.
Mitigation:
To mitigate this vulnerability, users should update Agoko CMS to a version that has patched this issue. It is also recommended to implement proper access controls and firewall rules to limit unauthorized access to the CMS.