Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://fenceposterror.github.io/2017/06/16/Hacking-For-Fun-And-Non-Profit.html | third party advisory exploit |