CVE-2020-15922
CRITICALMida eFramework < 2.9.0 - Authenticated Remote Code Execution via OS Command Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-15922. PoCs published by elbae.
AI-analyzed exploit summary This exploit targets CVE-2020-15922, an OS command injection vulnerability in Mida eFramework's PDC network.php page. It sends a crafted POST request with a reverse shell payload in the 'ipaddress0' parameter to achieve remote code execution.
Description
There is an OS Command Injection in Mida eFramework 2.9.0 that allows an attacker to achieve Remote Code Execution (RCE) with administrative (root) privileges. Authentication is required.
Exploits (1)
This exploit targets CVE-2020-15922, an OS command injection vulnerability in Mida eFramework's PDC network.php page. It sends a crafted POST request with a reverse shell payload in the 'ipaddress0' parameter to achieve remote code execution.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H