vendor:
CBAS-Web
by:
LiquidWorm
8.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: CBAS-Web
Affected Version From: 19.0.0
Affected Version To: 19.0.0
Patch Exists: YES
Related CWE: CVE-2019-10853, CVE-2019-10854
CPE: a:computrols:cbas-web
Other Scripts:
N/A
Platforms Tested: NA
2019
CBAS-Web 19.0.0 – Remote Code Execution
CBAS-Web Unauthenticated Remote Command Injection Exploit is a vulnerability that affects versions 19.0.0 and below. It uses two vulnerabilities for executing commands: an authorization bypass in the auth module (CVE-2019-10853) and a code execution vulnerability in the json.php endpoint (CVE-2019-10854).
Mitigation:
Upgrade to the latest version of CBAS-Web, which is not vulnerable to this exploit.