vendor:
Webuzo
by:
Mahendra
7,5
CVSS
HIGH
Remote OS Command Injection, Reflected Cross-site scripting, User Enumeration
78, 79, 200
CWE
Product Name: Webuzo
Affected Version From: 2.1.3
Affected Version To: 2.1.3
Patch Exists: YES
Related CWE: CVE-2013-6041, CVE-2013-6042, CVE-2013-6043
CPE: 2.1.3
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: CentOS release 6.2 (FINAL)
2013
Webuzo Multiple Vulnerabilities
Webuzo 2.1.3 has been identified with multiple security vulnerabilities, which can be exploited to perform remote OS command injection, execute malicious script and enumerate users. Authentication is not required to exploit these issues.
Mitigation:
Enforce HTTPS, validate user input, use security token assigned to particular IP address