Exploitation Summary
EIP tracks 2 public exploits for CVE-2013-3629.
PoCs published by Metasploit, including Metasploit module exploits/multi/http/ispconfig_php_exec.
AI-analyzed exploit summary This Metasploit module exploits an authenticated arbitrary PHP code execution vulnerability in ISPConfig by abusing the language settings export/import feature to upload and execute malicious PHP code.
Description
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
Exploits (2)
This Metasploit module exploits an authenticated arbitrary PHP code execution vulnerability in ISPConfig by abusing the language settings export/import feature to upload and execute malicious PHP code.
This Metasploit module exploits an authenticated arbitrary PHP code execution vulnerability in ISPConfig by abusing the language settings export/import feature to upload and execute malicious PHP code.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H