CVE-2014-7236
CRITICALTWiki Debugenableplugins Remote Code Execution
Title source: metasploitExploitation Summary
EIP tracks 3 public exploits for CVE-2014-7236.
PoCs published by Metasploit, m0nad, Netanel Rubin, h0ng10, including Metasploit module exploits/unix/http/twiki_debug_plugins.
AI-analyzed exploit summary This Metasploit module exploits a Perl eval injection vulnerability in TWiki's debug functionality, allowing remote code execution via the unsanitized 'debugenableplugins' parameter.
Description
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary Perl code via the debugenableplugins parameter to do/view/Main/WebHome.
Exploits (3)
This Metasploit module exploits a Perl eval injection vulnerability in TWiki's debug functionality, allowing remote code execution via the unsanitized 'debugenableplugins' parameter.
This exploit leverages a command injection vulnerability in TWiki's BackupRestorePlugin via the `debugenableplugins` parameter. It constructs a payload that executes arbitrary commands on the target system by bypassing input validation.
This Metasploit module exploits CVE-2014-7236, a remote code execution vulnerability in TWiki's debug functionality. It leverages unsanitized input in the `debugenableplugins` parameter to execute arbitrary Perl code via an eval statement.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N