CVE-2016-11017
CRITICALAKIPS Network Monitor 15.37-16.5 - Unauthenticated OS Command Injection via Username Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-11017. PoCs published by BrianWGray.
AI-analyzed exploit summary This exploit demonstrates an OS command injection vulnerability in AKIPS Network Monitor versions 15.37 through 16.5. The vulnerability allows an attacker to inject commands via the 'username' parameter during a failed login attempt, with the output returned in the login failure message.
Description
The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a failed login attempt returns the command-injection output to a limited login failure field). This is fixed in 16.6.
Exploits (1)
This exploit demonstrates an OS command injection vulnerability in AKIPS Network Monitor versions 15.37 through 16.5. The vulnerability allows an attacker to inject commands via the 'username' parameter during a failed login attempt, with the output returned in the login failure message.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H