SugarCRM REST Unserialize PHP Code...

- AV AC AU C I A
发布: 2016-09-08
修订: 2025-04-13

This Metasploit module exploits a PHP Object Injection vulnerability in SugarCRM CE <= 6.5.23 which could be abused to allow unauthenticated users to execute arbitrary PHP code with the permissions of the webserver. The dangerous unserialize() call exists in the '/service/core/REST/SugarRestSerialize.php' script. The exploit abuses the __destruct() method from the SugarCacheFile class to write arbitrary PHP code into the /custom directory.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息