vendor:
xbtitFM
by:
Anonymous
2.1
CVSS
LOW
SQL Injection, Path Traversal, Insecure File Upload
89
CWE
Product Name: xbtitFM
Affected Version From: 4.1.18
Affected Version To: 4.1.18
Patch Exists: NO
Related CWE: CVE-XXXX-XXXX (Not available at the time of writing)
CPE: a:xbtitfm:xbtitfm:4.1.18
Other Scripts:
https://www.infosecmatter.com/why-your-exploit-completed-but-no-session-was-created-try-these-fixes/, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/smb/ms17_010_eternalblue, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/local/dnsadmin_serverlevelplugindll, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/redis/file_upload, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/backupexec/ssl_uaf, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/local/cve_2020_0787_bits_arbitrary_file_move, https://www.infosecmatter.com/nessus-plugin-library/?id=91572, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/local/nscp_pe, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/unix/webapp/drupal_drupalgeddon2, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/gather/cloud_lookup
Platforms Tested:
2024
Multiple Vulnerabilities in xbtitFM 4.1.18
The unauthenticated SQL Injection and path traversal vulnerabilities in xbtitFM 4.1.18 and prior versions can be exploited without user interaction. An insecure file upload vulnerability requires enabling the file_hosting feature, which can be achieved by accessing an administrator account. These vulnerabilities can allow an attacker to extract database names, user information, and password hashes. Automated tools like sqlmap can be used to exploit these vulnerabilities and dump the database.
Mitigation:
To mitigate these vulnerabilities, it is recommended to update xbtitFM to the latest version, disable unnecessary features like file_hosting, and restrict access to administrative accounts.