vendor:
Albinator
by:
VietMafia and r0t, webDEViL w3bd3vil[at]gmail.com
7,5
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: Albinator
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Windows, Mac
Unknown
Albinator Multiple Parameter File Inclusion
Albinator Multiple Parameter File Inclusion is a vulnerability that allows an attacker to include a remote file on the web server. This vulnerability was discovered by VietMafia and r0t and was exploited by webDEViL w3bd3vil[at]gmail.com. The exploit uses a perl script to send a GET request to the vulnerable server with the path to the remote file and the command variable used in the php shell. The attacker can then execute arbitrary commands on the server.
Mitigation:
To mitigate this vulnerability, the web server should be configured to only allow access to trusted files and directories. Additionally, the web server should be configured to only allow access to files with specific extensions.