Mako Server 2.5 Command Injection

Discussion in 'News Aggregator' started by Packet Storm, 9 Nov 2017.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a vulnerability found in Mako Server version 2.5. It's possible to inject arbitrary OS commands in the Mako Server tutorial page through a PUT request to save.lsp. Attacker input will be saved on the victims machine and can be executed by sending a GET request to manage.lsp.

    Continue reading...
     

Share This Page

Loading...