vendor:
Myuploader
by:
S2K9
9,3
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Myuploader
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: Yes
Related CWE: N/A
CPE: a:myuploader:myuploader
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP2
2010
Myuploader >> upload shell exploit
A remote code execution vulnerability exists in Myuploader, which allows an attacker to upload a malicious shell and execute arbitrary code on the vulnerable system. The attacker can use the Dork to find vulnerable websites and then upload the shell to the ‘myuploader/uploaded-files/shell.php’ path. The attacker can then execute arbitrary code on the vulnerable system.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to update to the latest version of Myuploader.