CVE-2018-12465

CRITICAL

Micro Focus SMG <471 - Command Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2018-12465. PoCs published by Mehmet Ince, Mehmet Ince <[email protected]>, including Metasploit module exploits/linux/http/microfocus_secure_messaging_gateway.

AI-analyzed exploit summary This Metasploit module exploits CVE-2018-12465, a SQL injection and command injection vulnerability in MicroFocus Secure Messaging Gateway. It combines SQLi to create a user and command injection to execute arbitrary PHP code, achieving remote code execution.

Description

An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with CVE-2018-12464 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that used GWAVA product name (i.e. GWAVA 6.5).

Exploits (2)

exploitdb WORKING POC
by Mehmet Ince · rubywebappsphp
https://www.exploit-db.com/exploits/45083

This Metasploit module exploits CVE-2018-12465, a SQL injection and command injection vulnerability in MicroFocus Secure Messaging Gateway. It combines SQLi to create a user and command injection to execute arbitrary PHP code, achieving remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MicroFocus Secure Messaging Gateway
No auth needed
Prerequisites: Network access to the target · Vulnerable MicroFocus Secure Messaging Gateway instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Mehmet Ince <[email protected]> · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/http/microfocus_secure_messaging_gateway.rb

This Metasploit module exploits a SQL injection (CVE-2018-12464) and command injection (CVE-2018-12465) in MicroFocus Secure Messaging Gateway, allowing unauthenticated RCE via crafted API requests and session manipulation.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: MicroFocus Secure Messaging Gateway
No auth needed
Prerequisites: Network access to the target · Vulnerable endpoint exposed
devstral-2 · analyzed Apr 22, 2026 Full analysis →

References (3)

Core 3
Core References
Various Sources x_refsource_confirm
https://support.microfocus.com/kb/doc.php?id=7023133
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/45083/

Scores

CVSS v3 9.1
EPSS 0.8223
EPSS Percentile 99.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-78 CWE-77
Status published
Products (1)
microfocus/secure_messaging_gateway < 471
Published Jun 29, 2018
Tracked Since Feb 18, 2026