This Metasploit module exploits a vulnerability found in appRain's Content Management Framework (CMF), version 0.1.5 or less. By abusing the uploadify.php file, a malicious user can upload a file to the uploads/ directory without any authentication, which results in arbitrary code execution.
ecfbba7aea3ed45a511e747ceee47ff495011c2a8d081ea91351b0810e76fecc
appRain version 4.0.3 suffers from code execution and remote shell upload vulnerabilities.
b014b43098c86f53eda01d8e981d7501de7585a22761e3064f5a3c321fd72ba2
appRain version 4.0.3 suffers from multiple cross site request forgery vulnerabilities.
bc0624e70c181166f2c7d7b035b0a841ed95b529240c3be4138ef02231dc0146
appRain version 4.0.3 suffers from a path traversal vulnerability.
ed7376d3b7c28ede70e48ea7c3aae862305c0fb53ebf749f039c92e8edbdedb3
appRain version 4.0.3 suffers from multiple cross site scripting vulnerabilities.
54b49f563bacb15583f83004717acfdcaaae15e893f1340b353e9182863f9257
appRain version 3.0.2 suffers from a remote SQL injection vulnerability.
c9b7309b9491bac7d77ccf7c949a6825fbdcd06cedb8d1445051efe18501f410
Apprain version 3.0.2 suffers from multiple cross site request forgery vulnerabilities.
e606476fb827bd1dfe2fc1fc86cba2d171d51472da3a964744a23aa25cdf5e2d
appRain CMF versions 0.1.5 and below suffer from an unrestricted shell upload vulnerability in uploadify.php.
506aabb495e506a158aa2e70e4e9660ae29a6ff831efa1d2287c34419cba6dda
appRain versions 0.1.3 and 0.1.4-Alpha for both the Quick Start and Core editions suffer from multiple cross site scripting vulnerabilities.
52dd436444b837a85cbfd4a287fbb817919e848eaff7f9d393464836a3a9b5b2