vendor:
Revslider/Showbiz Pro
by:
Simo Ben youssef
7,5
CVSS
HIGH
Shell Upload
264
CWE
Product Name: Revslider/Showbiz Pro
Affected Version From: <= 3.0.95 (Revslider) / Version: <= 1.7.1 (Showbiz Pro)
Affected Version To: <= 3.0.95 (Revslider) / Version: <= 1.7.1 (Showbiz Pro)
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2014
Slider Revolution/Showbiz Pro shell upload exploit
Slider Revolution and Showbiz Pro fail to check authentication in revslider_admin.php/showbiz_admin.php allowing an unauthenticated attacker to abuse administrative features. Some of the features include: Creating/Deleting/Updating sliders, Importing/exporting sliders, Updading plugin.
Mitigation:
Ensure authentication is checked before allowing access to administrative features.