CVE-2015-5082
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 70%
from disclosure to weapon0 days
Published on NVDSep 28
1st PoCJun 29
metasploitJun 28
exploitation probability
70%top 1% of all CVEs
observed exploitation
nono source reports it
7 public exploit(s)
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW_PASSWORD_1 or (2) NEW_PASSWORD_2 parameter to cgi-bin/chpasswd.cgi.
Affected products
n/a · n/apublic PoCs found — 7✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/38096exploitdbwww.exploit-db.com/exploits/37426unverifiedexploitdbwww.exploit-db.com/exploits/37428unverifiedcve_referencepacketstormsecurity.com/files/133469/Endian-Firewall-Proxy-Password-Change-Command-Injection.htmlunverifiedcve_referencewww.exploit-db.com/exploits/38096/unverifiedcve_referencewww.exploit-db.com/exploits/37426/unverifiedcve_referencewww.exploit-db.com/exploits/37428/unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/133469/Endian-Firewall-Proxy-Password-Change-Command-Injection.htmlhttps://www.exploit-db.com/exploits/37426/https://www.exploit-db.com/exploits/37428/https://www.exploit-db.com/exploits/38096/http://www.rapid7.com/db/modules/exploit/linux/http/efw_chpasswd_exec