vendor:
Application Testing Suite
by:
Zhou Yu
8,8
CVSS
HIGH
Authentication Bypass and Arbitrary File Upload
284
CWE
Product Name: Application Testing Suite
Affected Version From: 12.4.0.2.0
Affected Version To: 12.4.0.2.0
Patch Exists: YES
Related CWE: CVE-2016-0492, CVE-2016-0491
CPE: a:oracle:application_testing_suite:12.4.0.2.0
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Win7 SP1 32-bit
2016
Oracle Application Testing Suite Authentication Bypass and Arbitrary File Upload Remote Exploit
This exploit allows an attacker to bypass authentication and upload arbitrary files to the Oracle Application Testing Suite. The attacker can then execute arbitrary code on the server. This exploit is based on two CVEs: CVE-2016-0492 and CVE-2016-0491.
Mitigation:
Ensure that authentication is properly enforced and that arbitrary file uploads are not allowed.