TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell commands via the cmd parameter in a direct request.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://secunia.com/advisories/28291 | third party advisory vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/39531 | vdb entry |
https://www.exploit-db.com/exploits/4861 | exploit |