packetstormsecurity.com
http://packetstormsecurity.com/files/157898/QuickBox-Pro-2.1.8-Remote-Code-Execution.html CVE-2020-13448
HIGH
QuickBox Pro 2.1.8 - Authenticated Remote Code Execution
Record summary
CVE-2020-13448 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBQuickBox Pro 2.1.8 - Authenticated Remote Code ExecutionExploitDB exploitby s1ghNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-13448 s1gh.sh
https://s1gh.sh/cve-2020-13448-quickbox-authenticated-rce