Bassmaster Batch Arbitrary JavaScript Injection Remote Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 31 Oct 2016.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits an un-authenticated code injection vulnerability in the bassmaster nodejs plugin for hapi. The vulnerability is within the batch endpoint and allows an attacker to dynamically execute JavaScript code on the server side using an eval. Note that the code uses a '\x2f' character so that we hit the match on the regex.

    Continue reading...
     

Share This Page

Loading...