Record summary

CVE-2014-5519 has a selected CVSS score of 7.5; EIP currently links 2 catalogued exploits.

Description

The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp. NOTE: some of these details are obtained from third party information.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBPhpWiki - Remote Command ExecutionExploitDB exploitby Benjamin HarrisNot analyzed1 file
ExploitDB

PoC details
MetasploitPhpwiki Ploticus Remote Code ExecutionMetasploit exploitby Benjamin Harris +1 moreNot analyzed1 file

Ruby

Metasploit

PoC details

References

8