module

Idera Up.Time Monitoring Station 7.4 post2file.php Arbitrary File Upload

Disclosed
11/18/2013
Created
05/30/2018

Description

This module exploits a vulnerability found in Uptime version 7.4.0 and 7.5.0.

The vulnerability began as a classic arbitrary file upload vulnerability in post2file.php,
which can be exploited by exploits/multi/http/uptime_file_upload_1.rb, but it was mitigated
by the vendor.

Although the mitigation in place will prevent uptime_file_upload_1.rb from working, it
can still be bypassed and gain privilege escalation, and allows the attacker to upload file
again, and execute arbitrary commands.

Authors

Denis AndzakovicEwerson Guimaraes(Crash) Gjoko Krstic(LiquidWorm)

Platform

PHP

Architectures

php

Module Options

To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

    msf > use exploit/multi/http/uptime_file_upload_2
    msf /(2) > show actions
        ...actions...
    msf /(2) > set ACTION < action-name >
    msf /(2) > show options
        ...show and set options...
    msf /(2) > run
  
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.