Exploitation Summary
EIP tracks 1 public exploit for CVE-2020-13448. PoCs published by s1gh.
AI-analyzed exploit summary This exploit leverages an authenticated command injection vulnerability in QuickBox Pro <= 2.1.8, allowing a low-privileged user to execute arbitrary commands as www-data. The PoC sends a crafted request to the target's process.php endpoint after authentication.
Description
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.
Exploits (1)
This exploit leverages an authenticated command injection vulnerability in QuickBox Pro <= 2.1.8, allowing a low-privileged user to execute arbitrary commands as www-data. The PoC sends a crafted request to the target's process.php endpoint after authentication.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H