CVE-2020-11699
HIGHSpamTitan 7.07 - Authenticated Remote Code Execution via certs-x.php fname Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-11699.
AI-analyzed exploit summary This is a functional exploit for multiple authenticated RCE vulnerabilities in SpamTitan Gateway 7.07, including command injection via improper validation of the 'fname' parameter in certs-x.php and PHP code evaluation via the 'jaction' parameter in mailqueue.php. The exploit includes reverse shell functionality and arbitrary file read capabilities.
Description
An issue was discovered in Titan SpamTitan 7.07. Improper validation of the parameter fname on the page certs-x.php would allow an attacker to execute remote code on the target server. The user has to be authenticated before interacting with this page.
Exploits (1)
This is a functional exploit for multiple authenticated RCE vulnerabilities in SpamTitan Gateway 7.07, including command injection via improper validation of the 'fname' parameter in certs-x.php and PHP code evaluation via the 'jaction' parameter in mailqueue.php. The exploit includes reverse shell functionality and arbitrary file read capabilities.
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H