Record summary

CVE-2018-16660 has a selected CVSS score of 8.8 (high); EIP currently links 2 catalogued exploits.

Description

A command injection vulnerability in PWS in Imperva SecureSphere 13.0.0.10 and 13.1.0.10 Gateway allows an attacker with authenticated access to execute arbitrary OS commands on a vulnerable installation.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBImperva SecureSphere 13 - Remote Command ExecutionExploitDB exploitby rsp3arNot analyzed1 file

linked to 3 vulnerabilities

ExploitDB

PoC details
MetasploitImperva SecureSphere PWS Command InjectionMetasploit exploitby rsp3ar <lukunming<at>gmail.comNot analyzed1 file

Ruby

Metasploit

PoC details

References

3