vendor:
VHCS
by:
RoMaNSoFt
7.5
CVSS
HIGH
Exploit
20
CWE
Product Name: VHCS
Affected Version From: 2.4.7.1
Affected Version To: 2.4.7.1
Patch Exists: YES
Related CWE: N/A
CPE: a:vhcs:vhcs
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2006
VHCS (version <= 2.4.7.1) PoC.
This exploit is for VHCS version <= 2.4.7.1. It allows an attacker to create an admin user with a predefined username and password. The exploit is launched by submitting a form with the target URL, username, and password. The username should not exist in the system.
Mitigation:
Upgrade to the latest version of VHCS.