Exploitation Summary
EIP tracks 3 public exploits for CVE-2018-17552.
PoCs published by Metasploit, kimstars, Pyriphlegethon, including Metasploit module exploits/multi/http/navigate_cms_rce.
AI-analyzed exploit summary This Metasploit module exploits an authentication bypass (CVE-2018-17552) and a file upload vulnerability (CVE-2018-17553) in Navigate CMS 2.8 and prior to achieve unauthenticated remote code execution. It bypasses login via SQL injection and uploads a malicious PHP file to execute arbitrary code.
Description
SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.
Exploits (3)
This Metasploit module exploits an authentication bypass (CVE-2018-17552) and a file upload vulnerability (CVE-2018-17553) in Navigate CMS 2.8 and prior to achieve unauthenticated remote code execution. It bypasses login via SQL injection and uploads a malicious PHP file to execute arbitrary code.
This PoC exploits an authentication bypass via SQL injection in the session cookie and uploads a malicious PHP file to achieve remote code execution (RCE). The exploit leverages a path traversal vulnerability to overwrite a legitimate file with a webshell.
This Metasploit module exploits an authentication bypass (CVE-2018-17552) and a path traversal vulnerability (CVE-2018-17553) in Navigate CMS 2.8 and prior to achieve unauthenticated remote code execution by uploading a malicious PHP file.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H