CVE-2014-4872
CVE-2014-4872
BMC Track-It! 11.3.0.355 does not require authentication on TCP port 9010, which allows remote attackers to upload arbitrary files, execute arbitrary code, or obtain sensitive credential and configuration information via a .NET Remoting request to (1) FileStorageService or (2) ConfigurationService.
Affected products
n/a · n/apublic PoCs found — 3
cve_referencepacketstormsecurity.com/files/128594/BMC-Track-it-Remote-Code-Execution-SQL-Injection.htmlunverifiedexploitdbwww.exploit-db.com/exploits/35032unverifiedexploitdbwww.exploit-db.com/exploits/34924unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →