BuilderEngine Arbitrary File Upload / Execution
Posted by deepcore on May 18, 2017 – 11:24 am
This Metasploit module exploits a vulnerability found in BuilderEngine 3.5.0 via elFinder 2.0. The jquery-file-upload plugin can be abused to upload a malicious file, which would result in arbitrary remote code execution under the context of the web server.
Post a reply
You must be logged in to post a comment.