CVE-2014-5073
VMTurbo Operations Manager <4.6 - Command Injection
Title source: llmDescription
vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands via shell metacharacters in the fileDate parameter in a DOWN call.
Exploits (2)
metasploit
WORKING POC
EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/http/vmturbo_vmtadmin_exec_noauth.rb
References (8)
Scores
EPSS
0.8827
EPSS Percentile
99.5%
Details
Status
published
Products (3)
vmturbo/operations_manager
4.0
vmturbo/operations_manager
4.5 (2 CPE variants)
vmturbo/operations_manager
< 4.6
Published
Aug 29, 2014
Tracked Since
Feb 18, 2026