CVE-2014-3080

IBM Global Console Manager <1.20.0.22575 XSS via KVM CGI or AVCT Alert Key

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-3080. PoCs published by Alejandro Alvarez Bravo.

AI-analyzed exploit summary The exploit demonstrates remote code execution (RCE) and arbitrary file read vulnerabilities in IBM 1754 GCM KVM switches (v1.20.0.22575 and prior). It leverages improper input sanitization in `systest.php` and `prodtest.php` to execute commands and read files, respectively.

Description

Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware before 1.20.20.23447 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to kvm.cgi or (2) the key parameter to avctalert.php.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Alejandro Alvarez Bravo · textremotephp
https://www.exploit-db.com/exploits/34132

The exploit demonstrates remote code execution (RCE) and arbitrary file read vulnerabilities in IBM 1754 GCM KVM switches (v1.20.0.22575 and prior). It leverages improper input sanitization in `systest.php` and `prodtest.php` to execute commands and read files, respectively.

Classification
Working Poc 95%
Attack Type
Rce | Info Leak
Complexity
Trivial
Reliability
Reliable
Target: IBM 1754 GCM KVM switch v1.20.0.22575 and prior
Auth required
Prerequisites: Valid session ID (avctSessionId) · Network access to the target device
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68777
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/34132/
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2014/Jul/113
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/93929

Scores

EPSS 0.0352
EPSS Percentile 87.8%

Details

CWE
CWE-79
Status published
Products (2)
ibm/global_console_manager_16_firmware < 1.20.0.22575
ibm/global_console_manager_32_firmware < 1.20.0.22575
Published Aug 17, 2014
Tracked Since Feb 18, 2026