CVE-2014-5300
Adaptive Computing Moab < 7.2.9 and 8 < 8.0.0 - Unauthenticated Authentication Bypass via Message Without Signature
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-5300. PoCs published by MWR InfoSecurity.
AI-analyzed exploit summary This exploit demonstrates an authentication bypass in Moab workload manager by omitting the <Signature> element in XML requests, allowing arbitrary command execution as any user, including root. The PoC includes a crafted XML payload to enable root job submissions.
Description
Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary users, and execute commands via a message without a signature.
Exploits (1)
This exploit demonstrates an authentication bypass in Moab workload manager by omitting the <Signature> element in XML requests, allowing arbitrary command execution as any user, including root. The PoC includes a crafted XML payload to enable root job submissions.