ReQuest Serious Play F3 Media Server 7.0.3 Unauthenticated Remote Code Execution
Posted by deepcore on October 20, 2020 – 4:15 pm
ReQuest Serious Play F3 Media Server version 7.0.3 suffers from an unauthenticated remote code execution vulnerability. Abusing the hidden ReQuest Internal Utilities page (/tools) from the services provided, an attacker can exploit the Quick File Uploader (/tools/upload.html) page and upload PHP executable files that results in remote code execution as the web server user.
Post a reply
You must be logged in to post a comment.