Praetorian503 Posted February 12, 2013 Report Share Posted February 12, 2013 IRIS Citations management tool suffers from a remote command execution vulnerability.A vulnerability exists in IRIS citations management tool which allows a low privileged attacker to execute arbitrary commands.Details can be found on my blog:https://infosecabsurdity.wordpress.com/2013/02/09/iris-citations-management-tool-post-auth-remote-command-execution/ PoC:http://[target]/[path]/index.php?p=add&import=spnro&code=a"+-T+0.1+||echo+`id`+>+/tmp/luls||"~ aeonSource: PacketStorm Quote Link to comment Share on other sites More sharing options...