vendor:
PodHawk
by:
CWH Underground
9,3
CVSS
HIGH
Unrestricted File Upload
N/A
CWE
Product Name: PodHawk
Affected Version From: 1.85
Affected Version To: 1.85
Patch Exists: YES
Related CWE: N/A
CPE: a:podhawk:podhawk
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Linux
2013
PodHawk Arbitary File Upload Vulnerability
This application has an upload feature that allows an authenticated user with Administrator roles or User roles to upload arbitrary files cause remote code execution by simply request it.
Mitigation:
Upgrade to the latest version of PodHawk