0.001
EPSS

CVE-2014-5090

CVSSv4: NA | CVSSv3: NA | CVSSv2: 6.5 | VMScore: 750 | EPSS: 0.00178 | KEV: Not Included
Published: 06/08/2014 Updated: 21/11/2024

Vulnerability Summary

admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin Panel.

Vulnerable Product Search on Vulmon Subscribe to Product

status2k status2k -

Exploits

# Exploit Title: Status2k Multiple Vulnerabilities/0days # Date: 6/20/2014 # Exploit Author: Shayan Sadigh (twittercom/r1pplex) | <ienjoyripples@gmailcom # Vendor Homepage: status2kcom/ # Version: All # Tested on: Linux/Windows # CVE : CVE-2014-5088, CVE-2014-5089, CVE-2014-5090, CVE-2014-5091, CVE-2014-5092, CVE-2014-5093, CVE-2014-5 ...
Status2k server monitoring software suffers from cross site scripting, remote command execution, information disclosure, and remote SQL injection vulnerabilities ...