Exploits / Vulnerability Discovered : 2023-08-04 |
Type : webapps |
Platform : php
This exploit / vulnerability Webutler v3.2 remote code execution (rce) is for educational purposes only and if it is used you will do on your own risk!
[+] Code ...
Exploit Title: Webutler v3.2 - Remote Code Execution (RCE)
Application: webutler Cms
Version: v3.2
Bugs: RCE
Technology: PHP
Vendor URL: https://webutler.de/en
Software Link: http://webutler.de/download/webutler_v3.2.zip
Date of found: 03.08.2023
Author: Mirabbas Ağalarov
Tested on: Linux
2. Technical Details & POC
========================================
steps:
1. login to account as admin
2. go to visit media
3.upload phar file
4. upload poc.phar file