vendor:
phpmyfaq
by:
elgCrew@safe-mail.net
9
CVSS
CRITICAL
Remote Command Execution
CWE
Product Name: phpmyfaq
Affected Version From: 1.6.2008
Affected Version To: 1.6.2008
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
phpmyfaq <= 1.6.8 Remote Command Execution Exploit
This exploit allows an attacker to execute arbitrary commands on a vulnerable phpmyfaq version. The vulnerability exists in the attachment.php file, which does not properly sanitize user input before executing commands. By uploading a malicious PHP file and making a specific POST request to the attachment.php file, an attacker can execute arbitrary commands on the server. The exploit also includes a proxy option for anonymity.
Mitigation:
Upgrade to a version higher than 1.6.8. Implement input validation and sanitization to prevent command injection attacks.