Description
Webutler v3.2 contains a remote code execution vulnerability that allows authenticated administrators to upload PHP files with system command execution. Attackers can upload a PHAR file with embedded system commands to the media browser and execute arbitrary commands by accessing the uploaded file.
Problem types
Unrestricted Upload of File with Dangerous Type
Product status
Credits
Mirabbas Ağalarov
References
www.exploit-db.com/exploits/51660
www.exploit-db.com/exploits/51660 (ExploitDB-51660)
webutler.de/en (WEButler Product Homepage)
www.vulncheck.com/...ode-execution-via-arbitrary-file-upload (VulnCheck Advisory: Webutler v3.2 Remote Code Execution via Arbitrary File Upload)
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.