vendor:
by:
ilo-- <ilo@reversing.org>
7.5
CVSS
HIGH
xmlrpc bug
CWE
Product Name:
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2005
xmlrpc exploit
This program is an xmlrpc exploit that targets a bug discovered by James from GulfTech Security Research. The exploit is specifically designed for Drupal, but other CMS such as Xoops and PhpNuke may also be vulnerable. The exploit allows for remote code execution by injecting a malicious command through the examples.getStateName method.
Mitigation:
Patch or upgrade the affected CMS to the latest version.