CVE-2017-8051
CRITICALTenable Appliance 3.5-4.4.0 - OS Command Injection via tns_appliance_session_user Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-8051. PoCs published by agix.
AI-analyzed exploit summary This exploit leverages an unauthenticated remote code execution vulnerability in Tenable Appliance versions prior to 4.5. It uses a crafted curl request to inject a bash reverse shell payload via the 'simpleupload.py' endpoint, resulting in a root shell.
Description
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.
Exploits (1)
This exploit leverages an unauthenticated remote code execution vulnerability in Tenable Appliance versions prior to 4.5. It uses a crafted curl request to inject a bash reverse shell payload via the 'simpleupload.py' endpoint, resulting in a root shell.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H