packetstormsecurity.com
http://packetstormsecurity.com/files/171542/BoxBilling-4.22.1.5-Remote-Code-Execution.html CVE-2022-3552
HIGH
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
Record summary
CVE-2022-3552 has a selected CVSS score of 7.2 (high); EIP currently links 1 catalogued exploit and 2 repository PoCs.
Description
Unrestricted Upload of File with Dangerous Type in GitHub repository boxbilling/boxbilling prior to 0.0.1.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
boxbilling/boxbillingBrowse boxbilling / boxbilling/boxbilling | CVE List | Before 0.0.1 | affected |
Proofs of concept
3Catalogued exploits
ExploitDBBoxBilling<=4.22.1.5 - Remote Code Execution (RCE)ExploitDB exploitby zetc0deNot analyzed1 file
Repository PoCs
GitHub0xk4b1r/CVE-2022-3552Repository PoCby 0xk4b1rStars: 8Not analyzed3 files
GitHubBakalMode/CVE-2022-3552Repository PoCby BakalModeStars: 2Not analyzed2 files
References
4github.com
https://github.com/boxbilling/boxbilling/commit/b6705995785eaa8653e876318c9b3d82060dc945 huntr.dev
https://huntr.dev/bounties/c6e2973d-386d-4667-9426-10d10828539b nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-3552