AROX School-ERP Pro Unauthenticated...

- AV AC AU C I A
发布: 2019-06-17
修订: 2025-04-13

This Metasploit module exploits a command execution vulnerability in AROX School-ERP. "import_stud.php" and "upload_fille.php" do not have session control. Session start/check functions in Line 8,9,10 are disabled with slashes. Therefore an unauthenticated user can execute the command on the system.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息