header-logo
Suggest Exploit
vendor:
bitrix.mpbuilder Bitrix module
by:
High-Tech Bridge Security Research Lab
9,6
CVSS
CRITICAL
PHP File Inclusion
98
CWE
Product Name: bitrix.mpbuilder Bitrix module
Affected Version From: 1.0.10
Affected Version To: 1.0.10
Patch Exists: YES
Related CWE: CVE-2015-8358
CPE: a:1c-bitrix:bitrix.mpbuilder
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015

bitrix.mpbuilder Bitrix module Vulnerability

High-Tech Bridge Security Research Lab discovered vulnerability in bitrix.mpbuilder Bitrix module, which can be exploited to include and execute arbitrary PHP file on the target system with privileges of the web server. The attacker will be able to execute arbitrary system commands and gain complete control over the website. Access to vulnerable modules requires administrative privileges, however the vulnerability can be used by anonymous users via CSRF vector. The vulnerability exists due to insufficient filtration of 'work[]' HTTP POST parameter in '/bitrix/admin/bitrix.mpbuilder_step2.php' script before using it in the include() PHP function. A remote attacker can include and execute arbitrary local file on the target system.

Mitigation:

Fixed by Vendor
Source

Exploit-DB raw data: