Wpis z mikrobloga

https://developer.joomla.org/security-centre/659-20161001-core-account-creation.html
https://developer.joomla.org/security-centre/660-20161002-core-elevated-privileges.html

So by combining these two vulnerabilities it is possible to create an Administrator user without any prior authentication. After that, you can upload a shell as an extension and get code excecution on the server.

#security #linux #devops #hackingnews
  • 2
  • Odpowiedz
  • Otrzymuj powiadomienia
    o nowych komentarzach