CVE-2020-11698
CRITICALTitanhq Spamtitan - Command Injection
Title source: ruleDescription
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server.
Exploits (2)
metasploit
WORKING POC
NORMAL
by Christophe De La Fuente, Felipe Molina · rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/freebsd/webapp/spamtitan_unauth_rce.rb
References (6)
Scores
CVSS v3
9.8
EPSS
0.8419
EPSS Percentile
99.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-77
Status
published
Products (1)
titanhq/spamtitan
7.07
Published
Sep 17, 2020
Tracked Since
Feb 18, 2026