Exploitation Summary
EIP tracks 3 public exploits for CVE-2012-0694.
PoCs published by Metasploit, EgiX, EgiX, juan vazquez, sinn3r, including Metasploit module exploits/unix/webapp/sugarcrm_unserialize_exec.
AI-analyzed exploit summary This Metasploit module exploits a PHP unserialize() vulnerability in SugarCRM <= 6.3.1, allowing authenticated users to execute arbitrary code via the '__destruct()' method of the 'SugarTheme' class. It writes a malicious PHP file to the web root and triggers payload execution via a crafted HTTP request.
Description
SugarCRM CE <= 6.3.1 contains scripts that use "unserialize()" with user controlled input which allows remote attackers to execute arbitrary PHP code.
Exploits (3)
This Metasploit module exploits a PHP unserialize() vulnerability in SugarCRM <= 6.3.1, allowing authenticated users to execute arbitrary code via the '__destruct()' method of the 'SugarTheme' class. It writes a malicious PHP file to the web root and triggers payload execution via a crafted HTTP request.
This exploit leverages a PHP object injection vulnerability in SugarCRM CE <= 6.3.1 via insecure unserialize() usage. It authenticates, crafts a malicious serialized SugarTheme object, and achieves remote code execution by writing a web shell to pathCache.php.
This Metasploit module exploits a PHP unserialize vulnerability in SugarCRM <= 6.3.1, allowing authenticated users to execute arbitrary code via the __destruct method of the SugarTheme class. It writes a malicious PHP file to the web root and triggers execution via a crafted HTTP request.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H