CVE-2014-5073

VMTurbo Operations Manager <4.6 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2014-5073. PoCs published by Metasploit, including Metasploit module exploits/unix/http/vmturbo_vmtadmin_exec_noauth.

AI-analyzed exploit summary This Metasploit module exploits a blind OS command injection vulnerability in VMTurbo Operations Manager 4.6 and prior via the vmtadmin.cgi endpoint. It supports both direct command execution and staged payload delivery for Linux targets.

Description

vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands via shell metacharacters in the fileDate parameter in a DOWN call.

Exploits (2)

exploitdb WORKING POC
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/34335

This Metasploit module exploits a blind OS command injection vulnerability in VMTurbo Operations Manager 4.6 and prior via the vmtadmin.cgi endpoint. It supports both direct command execution and staged payload delivery for Linux targets.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: VMTurbo Operations Manager <= 4.6
No auth needed
Prerequisites: Network access to the target's web interface · VMTurbo Operations Manager version <= 4.6 with build < 28657
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/http/vmturbo_vmtadmin_exec_noauth.rb

This Metasploit module exploits an unauthenticated OS command injection vulnerability in VMTurbo Operations Manager's web interface via the vmtadmin.cgi endpoint. It supports both direct command execution and staged payload delivery for Linux targets.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: VMTurbo Operations Manager <= 4.6 (build < 28657)
No auth needed
Prerequisites: Network access to the target's web interface · Vulnerable version of VMTurbo Operations Manager
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Third Party Advisory x_refsource_misc
http://secunia.com/secunia_research/2014-8/
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/95319
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/109572
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/58880
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/69225
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/34335

Scores

EPSS 0.7345
EPSS Percentile 99.4%

Details

Status published
Products (3)
vmturbo/operations_manager 4.0
vmturbo/operations_manager 4.5 (2 CPE variants)
vmturbo/operations_manager < 4.6
Published Aug 29, 2014
Tracked Since Feb 18, 2026