vendor:
Exam Hall Management System
by:
Davide 'yth1n' Bianchin
9,8
CVSS
HIGH
Unrestricted File Upload + RCE
434
CWE
Product Name: Exam Hall Management System
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux
2021
Exam Hall Management System 1.0 – Unrestricted File Upload + RCE (Unauthenticated)
This exploit allows an unauthenticated attacker to upload a malicious file to the Exam Hall Management System 1.0 web application and execute arbitrary code on the server. The vulnerability exists due to the lack of authentication and validation of the uploaded file. An attacker can exploit this vulnerability by uploading a malicious file containing arbitrary code to the web application. The malicious file can then be used to execute arbitrary code on the server.
Mitigation:
The best way to mitigate this vulnerability is to ensure that all uploaded files are properly validated and authenticated before being accepted by the web application.