Exploitation Summary
EIP tracks 2 public exploits for CVE-2010-20059.
PoCs published by Metasploit, MC, including Metasploit module exploits/multi/http/freenas_exec_raw.
AI-analyzed exploit summary This Metasploit module exploits an arbitrary command execution vulnerability in FreeNAS 0.7.2 < rev.5543 via the exec_raw.php page. It sends a crafted URI to write a PHP payload to the server and then triggers it to achieve remote code execution.
Description
FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The exec_raw.php script exposes a cmd parameter that is passed directly to the underlying shell without sanitation.
Exploits (2)
This Metasploit module exploits an arbitrary command execution vulnerability in FreeNAS 0.7.2 < rev.5543 via the exec_raw.php page. It sends a crafted URI to write a PHP payload to the server and then triggers it to achieve remote code execution.
This Metasploit module exploits a command injection vulnerability in FreeNAS 0.7.2 < rev.5543 via the exec_raw.php endpoint. It sends a crafted URI to write a PHP payload to the server and then triggers it to achieve remote code execution.
References (8)
Scores
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N