vendor:
Monstra CMS
by:
Ahmet Ümit BAYRAM
8.1
CVSS
CRITICAL
Remote Code Execution (RCE)
94
CWE
Product Name: Monstra CMS
Affected Version From: 3.0.4
Affected Version To: 3.0.4
Patch Exists: NO
Related CWE: CVE-2024-12345
CPE: a:monstra_cms:monstra:3.0.4
Other Scripts:
https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/dos/windows/ftp/iis75_ftpd_iac_bof, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/udp/udp_amplification, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/dos/http/apache_range_dos, https://www.infosecmatter.com/nessus-plugin-library/?id=79583, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/http/litespeed_source_disclosure, https://www.infosecmatter.com/nessus-plugin-library/?id=124719, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/unix/webapp/joomla_tinybrowser, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/scanner/http/axis_local_file_include, https://www.infosecmatter.com/nessus-plugin-library/?id=94372, https://www.infosecmatter.com/metasploit-module-library/?mm=auxiliary/dos/windows/rdp/ms12_020_maxchannelids
Platforms Tested: MacOS
2024
Monstra CMS 3.0.4 – Remote Code Execution (RCE)
The Monstra CMS 3.0.4 allows remote attackers to execute arbitrary code via crafted PHP code in a .chunk.php file.
Mitigation:
Ensure input validation and output sanitization to prevent arbitrary code execution. Regularly update the Monstra CMS to the latest version.