Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-14535. PoCs published by Ron Jost. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit leverages an OS command injection vulnerability in Trixbox 2.8.0.4 via the 'lang' parameter in /maint/modules/home/index.php. It sends a crafted HTTP request with a reverse shell payload to achieve unauthenticated remote code execution.
Description
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.
Exploits (1)
This exploit leverages an OS command injection vulnerability in Trixbox 2.8.0.4 via the 'lang' parameter in /maint/modules/home/index.php. It sends a crafted HTTP request with a reverse shell payload to achieve unauthenticated remote code execution.
Nuclei Templates (1)
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H