header-logo
Suggest Exploit
vendor:
WhatsUp Gold
by:
muts
9,3
CVSS
HIGH
Stored XSS, Blind SQLi, RCE
89, 89, 94
CWE
Product Name: WhatsUp Gold
Affected Version From: 15.02
Affected Version To: 15.02
Patch Exists: Yes
Related CWE: N/A
CPE: a:ipswitch:whatsup_gold:15.02
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012

Ipswitch WhatsUp Gold 15.02 Stored XSS – Blind SQLi – RCE

An attacker can modify their snmpd.conf file with malicious JavaScript as follows: sysName <script>alert(124)</script>pt>> In addition, there is a Blind SQL Injection vulnerability in the file 'WrVMwareHostList.asp'. By sending a specially crafted malicious JavaScript payload, the SQLi can be exploited to add a new database administrator to the system, leading to remote code execution. Blind SQLi Proof of Concept: WrVMwareHostList.asp?sGroupList=1;WAITFOR DELAY '0:0:10'--&sDeviceList=3 The JavaScript code below will exploit the blind SQL injection vulnerability, enable xp_cmdshell on the target, upload a reverse shell to the target, and execute it.

Mitigation:

Update to the latest version of Ipswitch WhatsUp Gold.
Source

Exploit-DB raw data: