Exploitation Summary
EIP tracks 2 public exploits for CVE-2018-12465.
PoCs published by Mehmet Ince, Mehmet Ince <[email protected]>, including Metasploit module exploits/linux/http/microfocus_secure_messaging_gateway.
AI-analyzed exploit summary This Metasploit module exploits CVE-2018-12465, a SQL injection and command injection vulnerability in MicroFocus Secure Messaging Gateway. It combines SQLi to create a user and command injection to execute arbitrary PHP code, achieving remote code execution.
Description
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with CVE-2018-12464 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that used GWAVA product name (i.e. GWAVA 6.5).
Exploits (2)
This Metasploit module exploits CVE-2018-12465, a SQL injection and command injection vulnerability in MicroFocus Secure Messaging Gateway. It combines SQLi to create a user and command injection to execute arbitrary PHP code, achieving remote code execution.
This Metasploit module exploits a SQL injection (CVE-2018-12464) and command injection (CVE-2018-12465) in MicroFocus Secure Messaging Gateway, allowing unauthenticated RCE via crafted API requests and session manipulation.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H