vendor:
nukeai beta3
by:
DeltahackingTEAM Code :Dr.Trojan&Dr.Pantagon
7,5
CVSS
HIGH
Remote Code Execution
CWE
Product Name: nukeai beta3
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested:
nukeai beta3 (util.php) Remote Code Execution Vulnerability
nukeai beta3 Download by default installation doesn't prevent any of the files in the modules/NukeAI directory from being accessed by a client. The modules/NukeAI file takes input passed to the script by util.php and writes it to $_POST["filename"].0 unsanatized in the modules/NukeAI descriptions directory.