CVE-2018-8097
CRITICALEve < 0.7.5 - Remote Code Execution via MongoDB Where Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2018-8097. PoCs published by SilentVoid13, StellarDriftLabs.
AI-analyzed exploit summary This is a Python-based Proof of Concept for CVE-2018-8097, which exploits a command injection vulnerability in PyEve versions < 0.7.5 via the 'where' filter parameter. The script constructs a malicious payload using Python's __import__ function to execute arbitrary system commands.
Description
io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter.
Exploits (2)
This is a Python-based Proof of Concept for CVE-2018-8097, which exploits a command injection vulnerability in PyEve versions < 0.7.5 via the 'where' filter parameter. The script constructs a malicious payload using Python's __import__ function to execute arbitrary system commands.
This is a functional Python-based PoC for CVE-2018-8097, exploiting a Python code injection vulnerability in Eve (a REST API framework) to perform blind file exfiltration via time-based side-channel attacks. It uses MongoDB ObjectId injection and a delay-based technique to extract file contents character by character.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H