vendor:
Millhouse-Project
by:
Chokri Hammedi
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Millhouse-Project
Affected Version From: 1.414
Affected Version To: 1.414
Patch Exists: NO
Related CWE:
CPE: a:thrsrossi:millhouse-project:1.414
Platforms Tested: Debian
2023
thrsrossi Millhouse-Project 1.414 – Remote Code Execution
This exploit allows an attacker to execute arbitrary code on the target system by exploiting a vulnerability in thrsrossi Millhouse-Project version 1.414. By sending a specially crafted request to the target's add_post_sql.php file, an attacker can upload a malicious PHP file and execute arbitrary commands on the target system.
Mitigation:
Update to a patched version of thrsrossi Millhouse-Project.