OpenCATS through 0.9.6 allows remote attackers to execute arbitrary code by uploading an executable file via lib/FileUtility.php.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://youtu.be/isiDISag7CM | third party advisory broken link |
https://github.com/opencats/OpenCATS/commit/b1af3bde1f68bec1c703ad66a3e390f15ed8ebe1 | third party advisory patch |
https://github.com/Nickguitar/RevCAT | patch third party advisory exploit |