vendor:
Group Office
by:
ADEO Security
8,8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: Group Office
Affected Version From: 3.5.9
Affected Version To: 3.5.9
Patch Exists: Yes
Related CWE: CVE-2010-3267
CPE: a:group-office:group-office
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux, Mac
2010
Group Office Remote Command Execution Vulnerability
Remote attacker can execute commands on the system that host target web application. Its high level vulnerability. Attacker needs gnupg module that installed. In json.php export method called with HTTP Request that's name fingerprint. In the export method, variable $fingerprint passed to run_cmd method.
Mitigation:
Upgrade to the latest version of Group Office.