This is a detailed technical writeup explaining a command injection vulnerability in Siaberry's login page. The vulnerability arises from unsanitized user input being passed directly to an exec() call in ActionPage.php, allowing arbitrary command execution.
Classification
Writeup 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target:Siaberry (version not specified)
No auth needed
Prerequisites:Network access to the Siaberry login page · Ability to send crafted HTTP POST requests