CVE-2017-6182
CRITICALSophos Web Appliance < 4.3.1.2 - Remote Command Injection via Report Generation Functions
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-6182. PoCs published by xort.
AI-analyzed exploit summary This Metasploit module exploits a remote command injection vulnerability in Sophos Web Appliance <= 4.3.0.2 via unsanitized JSON input in the reporting interface. It authenticates, injects commands into the 'trafficType' parameter, and either executes a specified command or deploys a payload for a reverse shell.
Description
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304.
Exploits (1)
This Metasploit module exploits a remote command injection vulnerability in Sophos Web Appliance <= 4.3.0.2 via unsanitized JSON input in the reporting interface. It authenticates, injects commands into the 'trafficType' parameter, and either executes a specified command or deploys a payload for a reverse shell.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H