vendor:
WebTester
by:
X-Cisadane
7,5
CVSS
HIGH
SQL Injection, Arbitrary File Upload, PHPInfo() Disclosure, Leftover install.php File
89, 264, 200, 564
CWE
Product Name: WebTester
Affected Version From: ALL
Affected Version To: ALL
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Google Chrome Version 26.0.1410.64 m (Windows XP SP 3 32-Bit English)
2013
WebTester 5.x Multiple Vulnerabilities
WebTester 5.x has a built-in WYSIWYG Editor, that is TinyMCE. The attacker can upload file through the TinyMCE File Manager. It can be found in tiny_mce/plugins/filemanager. The attacker can also exploit SQL Injection, PHPInfo() Disclosure and Leftover install.php File.
Mitigation:
Ensure that the web application is up to date and patched with the latest security updates. Restrict access to the web application and its components. Use a web application firewall to detect and block malicious requests.