CVE-2018-15767
HIGHDell OpenManage Network Manager < 6.5.3 - Incorrect Authorization via Sudoers Misconfiguration
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-15767. PoCs published by KoreLogic.
AI-analyzed exploit summary This exploit leverages default MySQL credentials in Dell OpenManage Network Manager to write a JSP backdoor to the web server directory, enabling remote command execution as root. It demonstrates privilege escalation via SQL injection and file write capabilities.
Description
The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfiguration in the /etc/sudoers file.
Exploits (1)
This exploit leverages default MySQL credentials in Dell OpenManage Network Manager to write a JSP backdoor to the web server directory, enabling remote command execution as root. It demonstrates privilege escalation via SQL injection and file write capabilities.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H