CVE-2020-11698
CRITICALSpamTitan 7.07 - Remote Code Execution via SNMP Community Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2020-11698.
PoCs published by Felipe Molina, Christophe De La Fuente, Felipe Molina, including Metasploit module exploits/freebsd/webapp/spamtitan_unauth_rce.
AI-analyzed exploit summary This exploit leverages unauthenticated command injection in SpamTitan's snmp-x.php to inject SNMP directives into snmpd.conf, enabling remote code execution via SNMP queries. It sets up a reverse shell using Perl.
Description
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp-x.php would allow a remote attacker to inject commands into the file snmpd.conf that would allow executing commands on the target server.
Exploits (2)
This exploit leverages unauthenticated command injection in SpamTitan's snmp-x.php to inject SNMP directives into snmpd.conf, enabling remote code execution via SNMP queries. It sets up a reverse shell using Perl.
This Metasploit module exploits an improper input sanitization vulnerability in SpamTitan Gateway versions 7.01, 7.02, 7.03, and 7.07 to inject SNMP configuration directives, leading to unauthenticated remote code execution as root.
References (6)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H