ID:4360 - Exploit for Arbitrary file upload in Lenovo ThinkManagement Console - CVE-2012-1195
Published: August 11, 2020
Lenovo ThinkManagement Console
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to insufficient validation of user-supplied input when uploading files in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service. A remote attacker can upload and execute arbitrary file on the server via the a PutUpdateFileCore command in a RunAMTCommand SOAP request.