CVE-2022-24637
60Vexday Risk Score
Corrige pronto. Ella tiene exploit funcional público.
ssvc Attendepss 99%
de la publicación al arma165 días
Publicada en NVD18 mar
1ª PoC+165d
metasploit18 mar
probabilidad de explotación
99%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
9 exploit(s) público(s)
Open Web Analytics (OWA) before 1.7.4 allows an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes. This occurs because files generated with '<?php (instead of the intended "<?php sequence) aren't handled by the PHP interpreter.
Productos afectados
n/a · n/aPoCs públicas encontradas — 9
exploitdbwww.exploit-db.com/exploits/51026no verificadogithubgithub.com/hupe1980/CVE-2022-24637★ 5githubgithub.com/Lay0us/CVE-2022-24637★ 5githubgithub.com/Pflegusch/CVE-2022-24637★ 4githubgithub.com/icebreack/CVE-2022-24637★ 4githubgithub.com/0xM4hm0ud/CVE-2022-24637★ 3githubgithub.com/0xRyuk/CVE-2022-24637★ 1cve_referencepacketstormsecurity.com/files/169811/Open-Web-Analytics-1.7.3-Remote-Code-Execution.htmlno verificadocve_referencepacketstormsecurity.com/files/171389/Open-Web-Analytics-1.7.3-Remote-Code-Execution.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
Referencias
http://packetstormsecurity.com/files/169811/Open-Web-Analytics-1.7.3-Remote-Code-Execution.htmlhttp://packetstormsecurity.com/files/171389/Open-Web-Analytics-1.7.3-Remote-Code-Execution.htmlhttps://devel0pment.de/?p=2494https://github.com/Open-Web-Analytics/Open-Web-Analytics/releases/tag/1.7.4