Vulnerability & Exploit Database

Back to search

Limesurvey Unauthenticated File Download

This module exploits an unauthenticated file download vulnerability in limesurvey between 2.0+ and 2.06+ Build 151014. The file is downloaded as a ZIP and unzipped automatically, thus binary files can be downloaded.

Free Metasploit Download

Get your copy of the world's leading penetration testing tool

 Download Now

Module Name

auxiliary/admin/http/limesurvey_file_download

Authors

  • Pichaya Morimoto
  • Christian Mehlmauer <FireFart [at] gmail.com>

References

Reliability

Development

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':

msf > use auxiliary/admin/http/limesurvey_file_download msf auxiliary(limesurvey_file_download) > show actions ...actions... msf auxiliary(limesurvey_file_download) > set ACTION <action-name> msf auxiliary(limesurvey_file_download) > show options ...show and set options... msf auxiliary(limesurvey_file_download) > run