Skip to content
COOEY

EXPOSURES › CVE-2021-36582

CVE-2021-36582

CRITICAL
DETAIL
SourceNVD · cve Published2021-09-14 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-36582 ↗
⚡ RCE SHAME 50/100 rce

In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to /Content/Template/root/reverse-shell.aspx and can be simply triggered by browsing that URL.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server. The files are uploaded to /Content/Template/root/reverse-shell.aspx and can be simply triggered by browsing that URL.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
Widely condemned for enabling remote shell upload in CMS
cooey ↗ severe-fallout -0.90
Damning disclosure of remote shell upload capability
"In Kooboo CMS 2.1.1.0, it is possible to upload a remote shell (e.g., aspx) to the server and then call upon it to receive a reverse shell from the victim server."
www.cvefind.com ↗ severe-fallout +0.00
Neutral database listing
SentinelOne ↗ severe-fallout +0.00
Neutral vulnerability database listing
www.npr.org ↗ severe-fallout +0.00
Irrelevant unrelated news
www.cbc.ca ↗ severe-fallout +0.00
Irrelevant unrelated news
CISA ↗ severe-fallout +0.00
Irrelevant unrelated advisory page
chromereleases.googleblog.com ↗ severe-fallout +0.00
Irrelevant unrelated release notes
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.