CVE-2018-12464
CRITICALMicro Focus Secure Messaging Gateway <471 - SQL Injection
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2018-12464.
PoCs published by Mehmet Ince, Mehmet Ince <[email protected]>, including Metasploit module exploits/linux/http/microfocus_secure_messaging_gateway.
AI-analyzed exploit summary This Metasploit module exploits CVE-2018-12465, a SQL injection and command injection vulnerability in MicroFocus Secure Messaging Gateway. It combines SQLi to create a user and command injection to execute arbitrary PHP code, achieving remote code execution.
Description
A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database. This can be exploited to create an administrative account and used in conjunction with CVE-2018-12465 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that use the GWAVA product name (i.e. GWAVA 6.5).
Exploits (2)
This Metasploit module exploits CVE-2018-12465, a SQL injection and command injection vulnerability in MicroFocus Secure Messaging Gateway. It combines SQLi to create a user and command injection to execute arbitrary PHP code, achieving remote code execution.
This Metasploit module exploits a SQL injection (CVE-2018-12464) and command injection (CVE-2018-12465) in MicroFocus Secure Messaging Gateway to achieve unauthenticated remote code execution. It chains SQLi to create a user and then leverages command injection via a malformed DKIM domain record.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H