CVE-2023-30258
CVE-2023-30258
Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
n/a · n/aPoCs públicas encontradas — 13
githubgithub.com/AdityaBhatt3010/TryHackMe-Room-Walkthrough-Billing★ 14githubgithub.com/tinashelorenzi/CVE-2023-30258-magnus-billing-v7-exploit★ 7githubgithub.com/Chocapikk/CVE-2023-30258★ 2githubgithub.com/kayl22/magnus_billing_7.3.0_RCE_CVE-2023-30258★ 1githubgithub.com/n00o00b/CVE-2023-30258-RCE-POC★ 1githubgithub.com/cyb3rk0ala/THM-MagnusBilling-CVE-2023-30258-Exploit★ 0githubgithub.com/gy741/CVE-2023-30258-setup★ 0githubgithub.com/sk00l/CVE-2023-30258★ 0githubgithub.com/abdullohqurbon0v/CVE-2023-30258-Exploit-For-Magnus-Billing-System★ 0githubgithub.com/CankunWang/Tryhackme_Billing★ 0githubgithub.com/estebanzarate/CVE-2023-30258-Magnus-Billing-v7-Command-Injection-PoC★ 0exploitdbwww.exploit-db.com/exploits/52170no verificadocve_referencepacketstormsecurity.com/files/175672/MagnusBilling-Remote-Command-Execution.htmlno verificado⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.
¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://packetstormsecurity.com/files/175672/MagnusBilling-Remote-Command-Execution.htmlhttps://eldstal.se/advisories/230327-magnusbilling.htmlhttps://github.com/magnussolution/magnusbilling7/commit/ccff9f6370f530cc41ef7de2e31d7590a0fdb8c3https://github.com/MarkLee131/awesome-web-pocs/blob/main/CVE-2023-30258.md