Mako Server 2.5 Command Injection...

- AV AC AU C I A
发布: 2017-11-08
修订: 2025-04-13

This Metasploit module exploits a vulnerability found in Mako Server version 2.5. It's possible to inject arbitrary OS commands in the Mako Server tutorial page through a PUT request to save.lsp. Attacker input will be saved on the victims machine and can be executed by sending a GET request to manage.lsp.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息