Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

Actual Analyzer Unauthenticated Command Execution

$
0
0
Hi All

URL: http://www.actualscripts.com/products/analyzer/

I tried to report this a month ago, but got no response from the
developers via the support form on their website, requesting a GPG
key. This is an old vulnerability I found while dusting off some
old hard drives.

Latest still vulnerable.

Brief:
-------------------------

The most popular web statistics tools delivers one big flat list
with statistics for any website. It is very easy in use but for
websites with small amount of pages only. Besides are provided the
primary opportunities for analyses of web site statistics only.


Details:
--------------------------

We control limited characters of an eval. Load commands into unused
variable and use backticks to execute command in short space.
Attached is a POC.

Pre-reqs are that you must know the domain of a website being
tracked by this script.

Many thanks,
Ben Harris

Email: bch@hush.ai


//The information contained within this publication is
//supplied "as-is"with no warranties or guarantees of fitness
//of use or otherwise. Bot24, Inc nor Bradley Sean Susser accepts
//responsibility for any damage caused by the use or misuse of
//this information


Viewing all articles
Browse latest Browse all 8064

Trending Articles