This Metasploit module exploits two vulnerabilities in the BYOB (Build Your Own Botnet) web GUI. It leverages an unauthenticated arbitrary file write that allows modification of the SQLite database, adding a new admin user. It also uses an authenticated command injection in the payload generation page. These vulnerabilities remain unpatched.
🛡️ VERIFIED CYBER INTELLIGENCE ID: #2361579
💾 BYOB Unauthenticated Remote Code Execution
⏱️ vor 653d 11h (16.10.2024 um 16:36 Uhr) 📂 💾 IT Security Tools 📡 Feed 🔗 Quelle: packetstormsecurity.com