vendor:
F3 Media Server
by:
LiquidWorm
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: F3 Media Server
Affected Version From: 7.0.3.4968 (Pro)
Affected Version To: 2.0.1.823
Patch Exists: YES
Related CWE: N/A
CPE: a:request:serious_play_f3_media_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: ReQuest Serious Play® OS v7.0.1, ReQuest Serious Play® OS v6.0.0, Debian GNU/Linux 5.0.9 (lenny)
2020
ReQuest Serious Play F3 Media Server 7.0.3 – Remote Code Execution (Unauthenticated)
The ReQuest ARQ F3 web server suffers from an unauthenticated remote code execution vulnerability. Abusing the hidden ReQuest Internal Utilities page (/tools) from the services provided, an attacker can exploit the Quick File Uploader (/tools/upload.html) page and upload PHP executable files that results in remote code execution as the web server user.
Mitigation:
Restrict access to the ReQuest Internal Utilities page and Quick File Uploader page.