vendor:
mma.php Backdoor
by:
Jay Turla
N/A
CVSS
N/A
Arbitrary File Upload
N/A
CWE
Product Name: mma.php Backdoor
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: php
2012
Th3 MMA mma.php Backdoor Arbitrary File Upload
This module exploits Th3 MMA mma.php Backdoor which allows an arbitrary file upload that leads to arbitrary code execution. This backdoor also echoes the Linux kernel version or operating system version because of the php_uname() function.
Mitigation:
The path of the mma.php file uploader backdoor should be set to '/mma.php'