module
Wordpress Plainview Activity Monitor RCE
Disclosed | Created |
---|---|
2018-08-26 | 2019-11-29 |
Disclosed
2018-08-26
Created
2019-11-29
Description
Plainview Activity Monitor Wordpress plugin is vulnerable to OS
command injection which allows an attacker to remotely execute
commands on underlying system. Application passes unsafe user supplied
data to ip parameter into activities_overview.php.
Privileges are required in order to exploit this vulnerability.
Vulnerable plugin version: 20161228 and possibly prior
Fixed plugin version: 20180826
command injection which allows an attacker to remotely execute
commands on underlying system. Application passes unsafe user supplied
data to ip parameter into activities_overview.php.
Privileges are required in order to exploit this vulnerability.
Vulnerable plugin version: 20161228 and possibly prior
Fixed plugin version: 20180826
Authors
LydA(c)ric LEFEBVRE
Leo LE BOUTER
Leo LE BOUTER
Platform
PHP
Architectures
php
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands ‘show options’ or ‘show advanced’:

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.