CVE-2006-3733
Cisco Security Monitoring, Analysis and Response System < 4.2.1 - Remote Code Execution via JMX-Console HtmlAdaptor
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2006-3733. PoCs published by Jon Hart.
AI-analyzed exploit summary This exploit targets an insecure JBoss installation in Cisco CS-MARS < 4.2.1, allowing remote command execution via the jmx-console. It provides multiple attack vectors including password changes, command execution, file uploads, and BeanShell script execution.
Description
jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allows remote attackers to gain privileges as the CS-MARS administrator and execute arbitrary Java code via an invokeOp action in the BSHDeployer jboss.scripts service name.
Exploits (1)
This exploit targets an insecure JBoss installation in Cisco CS-MARS < 4.2.1, allowing remote command execution via the jmx-console. It provides multiple attack vectors including password changes, command execution, file uploads, and BeanShell script execution.