BYOB Unauthenticated Remote Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 17 Oct 2024.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits two vulnerabilities in the BYOB (Build Your Own Botnet) web GUI. It leverages an unauthenticated arbitrary file write that allows modification of the SQLite database, adding a new admin user. It also uses an authenticated command injection in the payload generation page. These vulnerabilities remain unpatched.

    Continue reading...
     

Share This Page

Loading...