Exploitation Summary
EIP tracks 2 public exploits for CVE-2014-8686.
PoCs published by Metasploit, including Metasploit module exploits/linux/http/seagate_nas_php_exec_noauth.
AI-analyzed exploit summary This Metasploit module exploits an unauthenticated remote command execution vulnerability in Seagate Business NAS devices via a local file inclusion vulnerability in the CodeIgniter session cookie. It manipulates the session cookie to gain admin privileges and then injects a PHP payload to achieve remote code execution.
Description
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-based encryption scheme when the Mcrypt extension for PHP is not available.
Exploits (2)
This Metasploit module exploits an unauthenticated remote command execution vulnerability in Seagate Business NAS devices via a local file inclusion vulnerability in the CodeIgniter session cookie. It manipulates the session cookie to gain admin privileges and then injects a PHP payload to achieve remote code execution.
This Metasploit module exploits an unauthenticated remote command execution vulnerability in Seagate Business NAS devices via a local file inclusion flaw in the CodeIgniter session cookie. It manipulates the session cookie to gain admin privileges and injects a PHP payload to achieve RCE.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H