vendor:
eWebeditor
by:
Anonymous
8,8
CVSS
HIGH
Arbitrary File Upload, Database Disclosure, Administrator Bypass, Directory Traversal
434, 200, 264, 22
CWE
Product Name: eWebeditor
Affected Version From: ASP
Affected Version To: ASP
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
eWebeditor Arbitrary File Upload, Database Disclosure, Administrator Bypass, Directory Traversal Vulnerabilities
Arbitrary File Upload: An attacker can upload arbitrary files to the vulnerable server by exploiting the upload.asp script. Database Disclosure: An attacker can access the eweb editor database by exploiting the eweb editor.mdb script. Administrator Bypass: An attacker can bypass the administrator authentication by using the login.asp script. Directory Traversal: An attacker can traverse the directory structure of the vulnerable server by exploiting the upload.asp and browse.asp scripts.
Mitigation:
Ensure that the application is up to date and all security patches are applied. Restrict access to the application and its components to only authorized users. Ensure that the application is configured securely and all unnecessary features are disabled.