vendor:
AirMax Systems
by:
HackerOne
8,8
CVSS
HIGH
File Overwrite
434
CWE
Product Name: AirMax Systems
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
AirMax Systems File Overwrite Vulnerability
It's possible to overwrite any file (and create new ones) on AirMax systems, because the 'php2' (maybe because of a patch) don't verify the 'filename' value of a POST request. It's possible to a unauthenticated user to exploit this vulnerability. An attacker can take control over any AirMax Product with a simple forged http POST request.
Mitigation:
Ensure that the filename value of a POST request is properly verified.