Vulnerabilities > CVE-2015-2994 - Multiple Security vulnerability in SysAid

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
sysaid
exploit available
metasploit

Summary

Unrestricted file upload vulnerability in ChangePhoto.jsp in SysAid Help Desk before 15.2 allows remote administrators to execute arbitrary code by uploading a file with a .jsp extension, then accessing it via a direct request to the file in icons/user_photo/. <a href="http://cwe.mitre.org/data/definitions/434.html">CWE-434: Unrestricted Upload of File with Dangerous Type</a>

Vulnerable Configurations

Part Description Count
Application
Sysaid
4

Exploit-Db

  • idEDB-ID:41691
    last seen2018-11-30
    modified2015-06-03
    published2015-06-03
    reporterExploit-DB
    sourcehttps://www.exploit-db.com/download/41691
    titleSysAid Help Desk Administrator Portal &lt; 14.4 - Arbitrary File Upload (Metasploit)
  • descriptionSysAid Help Desk 14.4 - Multiple Vulnerabilities. CVE-2015-2993,CVE-2015-2994,CVE-2015-2995,CVE-2015-2996,CVE-2015-2997,CVE-2015-2998,CVE-2015-2999,CVE-2015-...
    idEDB-ID:43885
    last seen2018-01-25
    modified2015-06-10
    published2015-06-10
    reporterExploit-DB
    sourcehttps://www.exploit-db.com/download/43885/
    titleSysAid Help Desk 14.4 - Multiple Vulnerabilities

Metasploit

descriptionThis module exploits a file upload vulnerability in SysAid Help Desk. The vulnerability exists in the ChangePhoto.jsp in the administrator portal, which does not correctly handle directory traversal sequences and does not enforce file extension restrictions. While an attacker needs an administrator account in order to leverage this vulnerability, there is a related Metasploit auxiliary module which can create this account under some circumstances. This module has been tested in SysAid v14.4 in both Linux and Windows.
idMSF:EXPLOIT/MULTI/HTTP/SYSAID_AUTH_FILE_UPLOAD
last seen2020-06-06
modified2018-09-15
published2015-06-03
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/multi/http/sysaid_auth_file_upload.rb
titleSysAid Help Desk Administrator Portal Arbitrary File Upload

Packetstorm