CVE-2018-15768
MEDIUMDell OpenManage Network Manager < 6.5.0 - Insecure MySQL File System Access Control
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-15768. PoCs published by KoreLogic.
AI-analyzed exploit summary This exploit leverages default MySQL credentials in Dell OpenManage Network Manager to write a JSP backdoor to the web server directory, enabling remote command execution as root. It demonstrates privilege escalation via SQL injection and file write capabilities.
Description
Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file system for MySQL users due to insecure default configuration setting for the embedded MySQL database.
Exploits (1)
This exploit leverages default MySQL credentials in Dell OpenManage Network Manager to write a JSP backdoor to the web server directory, enabling remote command execution as root. It demonstrates privilege escalation via SQL injection and file write capabilities.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N