Bludit Directory Traversal Image File Upload
Posted by deepcore on November 13, 2019 – 2:10 pm
This Metasploit module exploits a vulnerability in Bludit. A remote user could abuse the uuid parameter in the image upload feature in order to save a malicious payload anywhere onto the server, and then use a custom .htaccess file to bypass the file extension check to finally get remote code execution.
Post a reply
You must be logged in to post a comment.