CVE-2013-6366

VMware Hyperic HQ 4.6.6 - Authenticated Remote Code Execution via Groovy Script Console

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-6366. PoCs published by Metasploit.

AI-analyzed exploit summary This Metasploit module exploits a vulnerability in VMware Hyperic HQ's Groovy script console to execute arbitrary OS commands via Java. It authenticates with provided credentials, retrieves a CSRF nonce, and crafts a payload to achieve remote code execution.

Description

The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().exec call.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotemultiple
https://www.exploit-db.com/exploits/28962

This Metasploit module exploits a vulnerability in VMware Hyperic HQ's Groovy script console to execute arbitrary OS commands via Java. It authenticates with provided credentials, retrieves a CSRF nonce, and crafts a payload to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMware Hyperic HQ 4.6.6 and earlier
Auth required
Prerequisites: Valid credentials for an application administrator account · Access to the Groovy script console
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/28962/

Scores

EPSS 0.0701
EPSS Percentile 93.3%

Details

CWE
CWE-94
Status published
Products (1)
vmware/hyperic_hq 4.6.6
Published Nov 04, 2013
Tracked Since Feb 18, 2026