CVE-2014-5468
HIGHRailo < 4.2.1.000 - Remote File Inclusion via Thumbnail CFM Request
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2014-5468.
PoCs published by Metasploit, Bryan Alexander <[email protected]>, bperry, including Metasploit module exploits/linux/http/railo_cfml_rfi.
AI-analyzed exploit summary This Metasploit module exploits a remote file include vulnerability in Railo (CVE-2014-5468) by leveraging a vulnerable <cffile> tag in thumbnail.cfm to download a malicious PNG file, which is then interpreted as ColdFusion markup to execute arbitrary commands.
Description
A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obtain sensitive information or execute arbitrary code.
Exploits (2)
This Metasploit module exploits a remote file include vulnerability in Railo (CVE-2014-5468) by leveraging a vulnerable <cffile> tag in thumbnail.cfm to download a malicious PNG file, which is then interpreted as ColdFusion markup to execute arbitrary commands.
This Metasploit module exploits a remote file inclusion vulnerability in Railo 4.2.1 by leveraging a vulnerable <cffile> tag in thumbnail.cfm to download a malicious PNG file, which is then interpreted as a CFM file due to directory traversal, leading to remote code execution.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H