CVE-2013-6618

Juniper Junos Authenticated RCE via J-Web PHP rsargs Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2013-6618. PoCs published by Sense of Security.

AI-analyzed exploit summary The advisory describes a remote code execution vulnerability in Juniper Junos J-Web via the `/jsdm/ajax/port.php` endpoint, allowing arbitrary PHP code execution with root privileges within a chroot. Privilege escalation can be achieved by hijacking admin sessions via `/tmp`.

Description

jsdm/ajax/port.php in J-Web in Juniper Junos before 10.4R13, 11.4 before 11.4R7, 12.1 before 12.1R5, 12.2 before 12.2R3, and 12.3 before 12.3R1 allows remote authenticated users to execute arbitrary commands via the rsargs parameter in an exec action.

Exploits (1)

exploitdb WRITEUP
by Sense of Security · textwebappsphp
https://www.exploit-db.com/exploits/29544

The advisory describes a remote code execution vulnerability in Juniper Junos J-Web via the `/jsdm/ajax/port.php` endpoint, allowing arbitrary PHP code execution with root privileges within a chroot. Privilege escalation can be achieved by hijacking admin sessions via `/tmp`.

Classification
Writeup 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Juniper Junos J-Web (all builds prior to 2013-02-28)
Auth required
Prerequisites: Access to J-Web interface · Read-only authentication
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit, URL Repurposed x_refsource_misc
http://www.senseofsecurity.com.au/advisories/SOS-13-003
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/29544
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/54731
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/62305
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/87011
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1029016

Scores

EPSS 0.1061
EPSS Percentile 95.2%

Details

CWE
CWE-20
Status published
Products (9)
juniper/junos 10.0
juniper/junos 10.1
juniper/junos 10.2
juniper/junos 10.3
juniper/junos 11.4
juniper/junos 12.1
juniper/junos 12.2
juniper/junos 12.3
juniper/junos < 10.4
Published Nov 05, 2013
Tracked Since Feb 18, 2026