CVE-2014-5073

VMTurbo Operations Manager <4.6 - Command Injection

Title source: llm

Description

vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands via shell metacharacters in the fileDate parameter in a DOWN call.

Exploits (2)

exploitdb WORKING POC
by Metasploit · rubyremotelinux
https://www.exploit-db.com/exploits/34335
metasploit WORKING POC EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/http/vmturbo_vmtadmin_exec_noauth.rb

Scores

EPSS 0.8827
EPSS Percentile 99.5%

Details

Status published
Products (3)
vmturbo/operations_manager 4.0
vmturbo/operations_manager 4.5 (2 CPE variants)
vmturbo/operations_manager < 4.6
Published Aug 29, 2014
Tracked Since Feb 18, 2026