nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-16660 CVE-2018-16660
HIGH
Imperva SecureSphere 13 - Remote Command Execution
Record summary
CVE-2018-16660 has a selected CVSS score of 8.8 (high); EIP currently links 2 catalogued exploits.
Description
A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated access to execute arbitrary OS commands on a vulnerable installation.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBImperva SecureSphere 13 - Remote Command ExecutionExploitDB exploitby rsp3arNot analyzed1 file
MetasploitImperva SecureSphere PWS Command InjectionMetasploit exploitby rsp3ar <lukunming<at>gmail.comNot analyzed1 file
References
3exploit-db.com
https://www.exploit-db.com/exploits/45542 imperva.com
https://www.imperva.com/products/securesphere/web-application-firewall