vendor:
Online Book Store
by:
Tib3rius
9.8
CVSS
CRITICAL
Unauthenticated Remote Code Execution
CWE
Product Name: Online Book Store
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:online_book_store:1.0
Platforms Tested: Ubuntu 16.04
2020
Online Book Store 1.0 – Unauthenticated Remote Code Execution
This exploit allows an attacker to execute remote code without authentication in the Online Book Store 1.0 application. By uploading a PHP web shell, the attacker can gain control of the target system and execute arbitrary commands.
Mitigation:
To mitigate this vulnerability, the vendor should implement proper input validation and authentication mechanisms to prevent unauthenticated remote code execution.