Vulnerabilities > CVE-2020-7209 - Unspecified vulnerability in HP Linuxki

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
hp
exploit available
metasploit

Summary

LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.

Exploit-Db

idEDB-ID:48483
last seen2020-05-18
modified2020-05-18
published2020-05-18
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/48483
titleHP LinuxKI 6.01 - Remote Command Injection

Metasploit

descriptionThis module exploits a vulnerability in LinuxKI Toolset <= 6.01 which allows remote code execution. The kivis.php pid parameter received from the user is sent to the shell_exec function, resulting in security vulnerability.
idMSF:EXPLOIT/LINUX/HTTP/LINUXKI_RCE
last seen2020-06-12
modified2020-06-09
published2020-05-29
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/exploits/linux/http/linuxki_rce.rb
titleLinuxKI Toolset 6.01 Remote Command Execution

Packetstorm