vendor:
Rukovoditel
by:
coiffeur
9.8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: Rukovoditel
Affected Version From: 2.6.1
Affected Version To: 2.6.1
Patch Exists: YES
Related CWE: CVE-2020-11819
CPE: a:rukovoditel:rukovoditel:2.6.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2020
Rukovoditel 2.6.1 – RCE
Rukovoditel 2.6.1 is vulnerable to a Remote Code Execution vulnerability. An attacker can exploit this vulnerability by uploading a malicious file to the server and then triggering it using a Local File Inclusion. This will allow the attacker to execute arbitrary code on the server.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update to the latest version of Rukovoditel.