CVE-2018-19646
CRITICALImperva SecureSphere <13.2.10 - Command Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-19646. PoCs published by rsp3ar.
AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in Imperva SecureSphere 13's PWS component, allowing unauthenticated or authenticated remote code execution via crafted parameters in the 'impcli' endpoint. The PoC uses base64-encoded commands injected into the 'installer-address' parameter.
Description
The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because command-line arguments are mishandled.
Exploits (1)
This exploit demonstrates a command injection vulnerability in Imperva SecureSphere 13's PWS component, allowing unauthenticated or authenticated remote code execution via crafted parameters in the 'impcli' endpoint. The PoC uses base64-encoded commands injected into the 'installer-address' parameter.
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H