rungga.blogspot.co.id
http://rungga.blogspot.co.id/2017/04/multiple-csrf-remote-code-execution.html CVE-2017-7447
HIGH
HelpDEZK 1.1.1 - Cross-Site Request Forgery / Code Execution
Record summary
CVE-2017-7447 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBHelpDEZK 1.1.1 - Cross-Site Request Forgery / Code ExecutionExploitDB exploitby rungga_reksyaNot analyzed1 file
References
597485vdb entry
http://www.securityfocus.com/bid/97485 github.com
https://github.com/albandes/helpdezk/issues/2 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-7447 41824exploit
https://www.exploit-db.com/exploits/41824