CVE-2017-7175
CRITICALnfsen < 1.3.7 - Remote Code Execution via Custom Output Format Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-7175. PoCs published by Paul Taylor.
AI-analyzed exploit summary This exploit leverages a command injection vulnerability in the 'customfmt' parameter of NfSen/AlienVault, allowing remote authenticated attackers to execute arbitrary commands as root. The PoC demonstrates a reverse shell payload using netcat.
Description
NfSen before 1.3.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the customfmt parameter (aka the "Custom output format" field).
Exploits (1)
This exploit leverages a command injection vulnerability in the 'customfmt' parameter of NfSen/AlienVault, allowing remote authenticated attackers to execute arbitrary commands as root. The PoC demonstrates a reverse shell payload using netcat.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H