Authenticated remote code execution (RCE) in Composr-CMS 10.0.39 and earlier allows remote attackers to execute arbitrary code via uploading a PHP shell through /adminzone/index.php?page=admin-commandr.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://github.com/sartlabs/0days/blob/main/Composr-CMS/Exploit.py | third party advisory exploit |
http://packetstormsecurity.com/files/171489/Composr-CMS-10.0.39-Remote-Code-Execution.html |