vendor:
Sahi Pro
by:
Özkan Mustafa Akkuş (AkkuS)
7.5
CVSS
HIGH
Unauthenticated Remote Command Execution
78
CWE
Product Name: Sahi Pro
Affected Version From: 8.0.0
Affected Version To: 8.0.0
Patch Exists: YES
Related CWE: N/A
CPE: a:sahi_technologies:sahi_pro:8.0.0
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Linux
2019
Sahi Pro V8.0.0 – Unauthenticated Remote Command Execution
Sahi Pro is vulnerable to Unauthenticated Remote Command Execution. It is possible to execute commands on the server using the function '_execute()'. This exploit creates a new sahi script that runs 'netcat' on the server and opens a shell session.
Mitigation:
Restrict access to the Sahi Pro application and ensure that the application is running on the latest version.