CVE-2013-6366
VMware Hyperic HQ 4.6.6 - Authenticated Remote Code Execution via Groovy Script Console
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-6366. PoCs published by Metasploit.
AI-analyzed exploit summary This Metasploit module exploits a vulnerability in VMware Hyperic HQ's Groovy script console to execute arbitrary OS commands via Java. It authenticates with provided credentials, retrieves a CSRF nonce, and crafts a payload to achieve remote code execution.
Description
The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary code via a Runtime.getRuntime().exec call.
Exploits (1)
This Metasploit module exploits a vulnerability in VMware Hyperic HQ's Groovy script console to execute arbitrary OS commands via Java. It authenticates with provided credentials, retrieves a CSRF nonce, and crafts a payload to achieve remote code execution.