Exploitation Summary
EIP tracks 2 public exploits for CVE-2014-5073.
PoCs published by Metasploit, including Metasploit module exploits/unix/http/vmturbo_vmtadmin_exec_noauth.
AI-analyzed exploit summary This Metasploit module exploits a blind OS command injection vulnerability in VMTurbo Operations Manager 4.6 and prior via the vmtadmin.cgi endpoint. It supports both direct command execution and staged payload delivery for Linux targets.
Description
vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands via shell metacharacters in the fileDate parameter in a DOWN call.
Exploits (2)
This Metasploit module exploits a blind OS command injection vulnerability in VMTurbo Operations Manager 4.6 and prior via the vmtadmin.cgi endpoint. It supports both direct command execution and staged payload delivery for Linux targets.
This Metasploit module exploits an unauthenticated OS command injection vulnerability in VMTurbo Operations Manager's web interface via the vmtadmin.cgi endpoint. It supports both direct command execution and staged payload delivery for Linux targets.