CVE-2018-16167
CRITICAL EXPLOITED IN THE WILD NUCLEILogonTracer < 1.2.0 - OS Command Injection
Title source: llmExploitation Summary
CVE-2018-16167 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 2 public exploits from researchers including g0ldm45k, dnr6419. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit targets CVE-2018-16167 in LogonTracer 1.2.0, achieving unauthenticated remote code execution by injecting a reverse shell payload into the 'timezone' parameter of the /upload endpoint. The payload uses Python to spawn a shell and connect back to the attacker.
Description
LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Exploits (2)
This exploit targets CVE-2018-16167 in LogonTracer 1.2.0, achieving unauthenticated remote code execution by injecting a reverse shell payload into the 'timezone' parameter of the /upload endpoint. The payload uses Python to spawn a shell and connect back to the attacker.
This is a functional exploit for CVE-2018-16167, targeting LogonTracer 1.2.0 and earlier. It achieves unauthenticated remote code execution by injecting a reverse shell payload into the 'timezone' parameter of the /upload endpoint.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H