Oracle BeeHive 2 Arbitrary File Upload
Posted by deepcore on December 3, 2015 – 7:12 pm
This Metasploit module exploits a vulnerability found in Oracle BeeHive. The prepareAudioToPlay method found in voice-servlet can be abused to write a malicious file onto the target machine, and gain remote arbitrary code execution under the context of SYSTEM. Authentication is not required to exploit this vulnerability.
Post a reply
You must be logged in to post a comment.