TeemIp IPAM Command Injection...

- AV AC AU C I A
发布: 2019-04-03
修订: 2025-04-13

This Metasploit module exploits a command injection vulnerability in TeemIp versions prior to 2.4.0. The "new_config" parameter of "exec.php" allows you to create a new PHP file with the exception of config information. The malicious PHP code sent is executed instantaneously and is not saved on the server. The vulnerability can be exploited by an authorized user (Administrator). Module allows remote command execution by sending php payload with parameter 'new_config'.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息