vendor:
aidiCMS
by:
Egidio Romano aka EgiX
9.3
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: aidiCMS
Affected Version From: 3.55
Affected Version To: 3.55
Patch Exists: YES
Related CWE: N/A
CPE: a:aidicms:aidicms:3.55
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2011
aidiCMS v3.55 (ajax_create_folder.php) Remote Code Execution Exploit
aidiCMS v3.55 is affected by the vulnerability that allows an attacker to execute arbitrary code on the vulnerable system. This is achieved by sending a specially crafted POST request to the ajax_create_folder.php script, which contains a malicious payload that is written to a file called foo.php. The attacker can then execute arbitrary code by sending a specially crafted GET request to the foo.php script, which contains a base64 encoded command in the Cmd header.
Mitigation:
Upgrade to the latest version of aidiCMS