vendor:
Q-News
by:
FireShot, Jacopo Vuga
9.3
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: Q-News
Affected Version From: 2
Affected Version To: 2
Patch Exists: NO
Related CWE: N/A
CPE: a:q-news:q-news:2.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2009
Q-News RCE Exploit
This exploit is for the q-news 2.0 software. It is a remote command execution vulnerability which allows an attacker to execute arbitrary commands on the vulnerable system. The exploit uses a malicious URL to inject malicious code into the settings.php file which is then used to execute arbitrary commands on the vulnerable system.
Mitigation:
The best way to mitigate this vulnerability is to ensure that the settings.php file is not writable by any user or process.