vendor:
Ignition
by:
cOndemned
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Ignition
Affected Version From: 1.3
Affected Version To: 1.3
Patch Exists: NO
Related CWE: Not mentioned
CPE: Not mentioned
Platforms Tested: Not mentioned
Not mentioned
Ignition 1.3 Remote Code Execution Exploit
The Ignition 1.3 version is vulnerable to remote code execution. Attackers can overwrite the settings.php file by sending a specially crafted POST request and injecting malicious code into one of the variables. This allows attackers to execute arbitrary commands on the target server.
Mitigation:
Update to a patched version of Ignition. Ensure that user input is properly validated and sanitized to prevent code injection.