CVE-2014-5091
CRITICALstatus2k 2.5 - Remote Code Execution via Multies Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-5091. PoCs published by Shayan S.
AI-analyzed exploit summary This is a detailed writeup describing multiple vulnerabilities in Status2k software, including XSS, SQLi, command injection, RCE via eval() backdoor, template manipulation, design flaws, and information leaks. It provides PoC examples and CVE assignments for each issue.
Description
A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.
Exploits (1)
This is a detailed writeup describing multiple vulnerabilities in Status2k software, including XSS, SQLi, command injection, RCE via eval() backdoor, template manipulation, design flaws, and information leaks. It provides PoC examples and CVE assignments for each issue.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H