CVE-2015-2993
SysAid < 15.1 - Unauthenticated Arbitrary File Write via fileName Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2015-2993.
Includes Metasploit module auxiliary/admin/http/sysaid_admin_acct.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in SysAid Help Desk 14.4, including unauthenticated administrator account creation, file upload via directory traversal, arbitrary file download, and SQL injection. It provides detailed technical steps and payloads for each vulnerability.
Description
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount or (2) write to arbitrary files via the fileName parameter to /userentry.
Exploits (2)
The exploit demonstrates multiple vulnerabilities in SysAid Help Desk 14.4, including unauthenticated administrator account creation, file upload via directory traversal, arbitrary file download, and SQL injection. It provides detailed technical steps and payloads for each vulnerability.
This Metasploit module exploits an unauthenticated administrator account creation vulnerability in SysAid Help Desk by sending a crafted HTTP GET request to the 'createnewaccount' endpoint. It creates a new admin account with specified credentials, though verification must be done manually.