Zpanel 10.1.0 Remote Unauthenticated Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 21 Oct 2015.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits an information disclosure vulnerability found in Zpanel versions 10.1.0 and below. The vulnerability is due to a vulnerable version of pChart allowing remote, unauthenticated, users to read arbitrary files found on the filesystem. This particular module utilizes this vulnerability to identify the username/password combination of the MySQL instance. With the credentials the attackers can login to PHPMyAdmin and execute SQL commands to drop a malicious payload on the filesystem and call it leading to remote code execution.

    Continue reading...
     

Share This Page

Loading...