ZeroHour

CVE-2020-13166

PoC ×2
CVSS 3.1
9.8 critical
EPSS
78%p100
Published
()
Modified
Description

The management tool in MyLittleAdmin 3.8 allows remote attackers to execute arbitrary code because machineKey is hardcoded (the same for all customers' installations) in web.config, and can be used to send serialized ASP code.

Vendors
mylittletools
Products
mylittleadmin
Weakness
CWE-798
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.