vendor:
Up.Time Monitoring Station
by:
Denis Andzakovic
N/A
CVSS
N/A
Arbitrary File Upload
N/A
CWE
Product Name: Up.Time Monitoring Station
Affected Version From: 7.0
Affected Version To: 7.2
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: PHP
2013
Idera Up.Time Monitoring Station 7.0 post2file.php Arbitrary File Upload
This module exploits an arbitrary file upload vulnerability found within the Up.Time monitoring server 7.2 and below. A malicious entity can upload a PHP file into the webroot without authentication, leading to arbitrary code execution.
Mitigation:
Vendor fixed Up.Time to prevent this vulnerability, but it was not properly mitigated.