Lunar CMS 'connector.php' Multiple Remote Command Execution Vulnerabilities
BID:68154
Info
Lunar CMS 'connector.php' Multiple Remote Command Execution Vulnerabilities
| Bugtraq ID: | 68154 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 23 2014 12:00AM |
| Updated: | Jun 23 2014 12:00AM |
| Credit: | LiquidWorm |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Lunar CMS 'connector.php' Multiple Remote Command Execution Vulnerabilities
Lunar CMS is prone to multiple remote command-execution vulnerabilities because the application fails to sufficiently sanitize user-supplied input data.
An attacker may leverage these issues to execute arbitrary commands in the context of the affected application.
Lunar CMS 3.3 is vulnerable; other versions may also be affected.
Lunar CMS is prone to multiple remote command-execution vulnerabilities because the application fails to sufficiently sanitize user-supplied input data.
An attacker may leverage these issues to execute arbitrary commands in the context of the affected application.
Lunar CMS 3.3 is vulnerable; other versions may also be affected.
Exploit / POC
Lunar CMS 'connector.php' Multiple Remote Command Execution Vulnerabilities
The following exploit is available:
The following exploit is available:
Solution / Fix
Lunar CMS 'connector.php' Multiple Remote Command Execution Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Lunar CMS 'connector.php' Multiple Remote Command Execution Vulnerabilities
References:
References: