Exploitation Summary
EIP tracks 1 public exploit for CVE-2013-4864. PoCs published by Trustwave's SpiderLabs.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in MiCasaVerde VeraLite, including path traversal, insufficient authorization checks, and CSRF. It provides proof-of-concept code for arbitrary file disclosure, privilege escalation via firmware updates, and remote code execution through Lua code injection.
Description
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url parameter to cgi-bin/cmh/proxy.sh, related to a Server-Side Request Forgery (SSRF) issue.
Exploits (1)
The exploit demonstrates multiple vulnerabilities in MiCasaVerde VeraLite, including path traversal, insufficient authorization checks, and CSRF. It provides proof-of-concept code for arbitrary file disclosure, privilege escalation via firmware updates, and remote code execution through Lua code injection.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H