OrientDB 2.2.x Remote Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 8 Oct 2017.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module leverages a privilege escalation on OrientDB to execute unsandboxed OS commands. All versions from 2.2.2 up to 2.2.22 should be vulnerable.

    Continue reading...
     

Share This Page

Loading...