packetstormsecurity.com
http://packetstormsecurity.com/files/159314/Mida-eFramework-2.8.9-Remote-Code-Execution.html CVE-2020-15922
CRITICAL
Mida eFramework 2.8.9 - Remote Code Execution
Record summary
CVE-2020-15922 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMida eFramework 2.8.9 - Remote Code ExecutionExploitDB exploitby elbaeNot analyzed1 file
References
3elbae.github.io
https://elbae.github.io/jekyll/update/2020/07/14/vulns-01.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-15922