Full title: SePortal 2.5 SQL Injection / Remote Code Execution Exploit Category: remote exploits Platform: php This Metasploit module exploits a vulnerability found in SePortal version 2.5. When logging in as any non-admin user, it's possible to retrieve the admin session from the database through SQL injection. The SQL injection vulnerability exists in the "staticpages.php" page. This hash can be used to take over the admin user session. After logging in, the "/admin/downloads.php" page will be used to upload arbitrary code. # 0day.today @ http://0day.today/