lists.openwall.net
http://lists.openwall.net/full-disclosure/2018/02/27/1 CVE-2018-7665
CRITICAL
ClipBucket beats_uploader Unauthenticated Arbitrary File Upload
Record summary
CVE-2018-7665 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
An issue was discovered in ClipBucket before 4.0.0 Release 4902. A malicious file can be uploaded via the name parameter to actions/beats_uploader.php or actions/photo_uploader.php, or the coverPhoto parameter to edit_account.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
MetasploitClipBucket beats_uploader Unauthenticated Arbitrary File UploadMetasploit exploitby Touhid M.Shaikh <admin@touhidshaikh.com> +1 moreNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-7665 sec-consult.com
https://www.sec-consult.com/en/blog/advisories/os-command-injection-arbitrary-file-upload-sql-injection-in-clipbucket/index.html