CVE-2012-3399
Basilic 1.5.14 - Remote Command Execution via Config/diff.php File Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2012-3399.
PoCs published by Metasploit, lcashdollar, sinn3r, juan vazquez, including Metasploit module exploits/unix/webapp/basilic_diff_exec.
AI-analyzed exploit summary This Metasploit module exploits a metacharacter injection vulnerability in Basilic 1.5.14's diff.php script, allowing unauthenticated remote command execution as the www-data user. The exploit sends a crafted GET request with payload-encoded parameters to trigger arbitrary command execution.
Description
Config/diff.php in Basilic 1.5.14 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter.
Exploits (2)
This Metasploit module exploits a metacharacter injection vulnerability in Basilic 1.5.14's diff.php script, allowing unauthenticated remote command execution as the www-data user. The exploit sends a crafted GET request with payload-encoded parameters to trigger arbitrary command execution.
This Metasploit module exploits a metacharacter injection vulnerability in Basilic 1.5.14's diff.php script, allowing unauthenticated remote command execution as the www-data user. The exploit sends a crafted GET request with the payload embedded in the 'file' parameter.