CVE-2021-47903
HIGHLiteSpeed Web Server Enterprise 5.4.11 - Command Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2021-47903. PoCs published by SunCSR.
AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in LiteSpeed Web Server Enterprise 5.4.11. It leverages authenticated access to inject a reverse shell payload via the 'Command' field in the External App configuration, leading to remote code execution.
Description
LiteSpeed Web Server Enterprise 5.4.11 contains an authenticated command injection vulnerability in the external app configuration interface. Authenticated administrators can inject shell commands through the 'Command' parameter in the server configuration, allowing remote code execution via path traversal and bash command injection.
Exploits (1)
This exploit demonstrates a command injection vulnerability in LiteSpeed Web Server Enterprise 5.4.11. It leverages authenticated access to inject a reverse shell payload via the 'Command' field in the External App configuration, leading to remote code execution.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H