An issue was discovered in post2file.php in Up.Time Monitoring Station 7.5.0 (build 16) and 7.4.0 (build 13). It allows an attacker to upload an arbitrary file, such as a .php file that can execute arbitrary OS commands.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
http://www.zeroscience.mk/en/vulnerabilities/ZSL-2015-5254.php | third party advisory exploit |
https://www.exploit-db.com/exploits/37888/ | exploit vdb entry third party advisory |
https://www.rapid7.com/db/modules/exploit/multi/http/uptime_file_upload_2 | third party advisory |