CVE-2023-50917
72Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 38%
from disclosure to weapon0 days
Published on NVDDec 15
1st PoCOct 29
metasploitDec 15
VulnCheck+672d
exploitation probability
38%top 2% of all CVEs
observed exploitation
yesVulnCheck
2 public exploit(s)
MajorDoMo (aka Major Domestic Module) before 0662e5e allows command execution via thumb.php shell metacharacters. NOTE: this is unrelated to the Majordomo mailing-list manager.
Affected products
n/a · n/apublic PoCs found — 2
vulncheckvulncheck.com/xdb/69d8b733f2b5unverifiedvulncheckvulncheck.com/xdb/19f100aff369unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/176273/MajorDoMo-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/176669/MajorDoMo-Command-Injection.htmlhttp://seclists.org/fulldisclosure/2023/Dec/19https://github.com/sergejey/majordomo/commit/0662e5ebfb133445ff6154b69c61019357092178https://github.com/sergejey/majordomo/commit/3ec3ffb863ea3c2661ab27d398776c551f4daaac