Get a Pentest and security assessment of your IT network.

News

A flaw in Concrete5 CMS could have allowed website takeover

A remote code execution (RCE) vulnerability affecting the Concrete5 CMS exposed numerous servers to full takeover, experts warn. The vulnerability was discovered by researchers from Edgescan, it could be exploited by an attacker to inject a reverse shellcode into vulnerable web servers allowing him to take full control of them. Experts pointed out that the flaw could have been exploited to add PHP extension in the list of allowed extensions and then upload the file to execute arbitrary commands. A step by step procedure to reproduce to exploit the flaw was published on HackerOne.”]

Source: https://securityaffairs.co/wordpress/107294/security/concrete5-cms-rce.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Take note, next week update Adobe Reader and Acrobat to fix critical flaws

News

Linux bug leaves 1.4 billion Android users vulnerable to hijacking attacks