Skip to main content
Fortra Data Classification Core Security Logo
Secondary Navigation
  • Fortra.com
  • Contact Us
  • Support
  • PRICING
    • Column 1
      • Core Solutions
        • Core Impact
        • Penetration Testing Services
    • Column 2
      • Interoperable Solutions
        • Cobalt Strike
        • Outflank Security Tooling (OST)
        • Bundles and Suites
    • View all Solutions
    • Column 1
      • Healthcare
      • Financial Services
      • Federal Government
    • View all Industries
    • Blogs
    • Guides
    • Training
    • Webinars & Events
    • View all Resources
    • Exploits
    • Impacket
    • View all
  • About

Read more about Drupal Form API Ajax Requests Remote OS Command Injection Exploit
Drupal is prone to an OS command injection vulnerability that allows attackers to take advantage of an improper validation of user-supplied data in the Form API Ajax Requests.
Read more about HPE Operations Orchestration Central Java Deserialization Vulnerability Remote Code Execution Exploit
A input validation vulnerability in HPE Operations Orchestration product all versions prior to 10.80, allows for the execution of code remotely.
Read more about Symantec Messaging Gateway performRestore OS Command Injection Exploit
Symantec Messaging Gateway is prone to an Authentication Bypass vulnerability that allows attackers to take advantage of an improper validation of user-supplied data in the RestoreAction.performRestore method.



An attacker can leverage this vulnerability to execute arbitrary code in the context of root.
Read more about HPE iMC WebDMDebugServlet Java Deserialization Vulnerability Remote Code Execution Exploit
HPE Intelligent Management Center is prone to a remote vulnerability that allows attackers to take advantage of an improper validation of user-supplied data, which can result in deserialization of untrusted data in WebDMDebugServlet.

An attacker can leverage this vulnerability to execute arbitrary code in the context of SYSTEM.
Read more about pfSense system groupmanager Command Execution Exploit
This module exploits a post authentication vulnerability in pfSense by abusing the system_groupmanager.php page which allows users to get Code Execution.
Read more about TrendMicro Officescan Widget Remote Command Execution Exploit
TrendMicro is prone to an abuse in the talker.php function to get authentication bypass, combined with the mod TMCSS user-supplied unvalidated input before using it to execute a system calls leads us to execute arbitrary code.
Read more about REDDOXX Appliance ExecuteDiag Remote Command Injection Exploit
This module exploits a command injection vulnerability in REDDOXX Appliance to install an agent.
Read more about Apache Struts 2 REST Plugin XStream Exploit
This module exploits a Java deserialization bug in Apache Struts REST XStreamHandler which allows users to get Code Execution.
Read more about OrientDB Remote Command Execution Exploit
This module exploits a privilege escalation vulnerability in OrientDB by abusing SQL queries on OUser/ORole without the privileges which allows users to get Code Execution.
Read more about WordPress PHPMailer Remote Code Execution Exploit
This module exploits a PHPMailer vulnerability in WordPress abusing a Lost Password recovery action and installs an agent.

Pagination

  • Previous page ‹‹
  • Page 8
  • Next page ››
Subscribe to OS Command Injection
Fortra logo
  • Email Core Security Email Us
  • X Find us on X
  • LinkedIn Find us on LinkedIn
  • YouTube Find us on YouTube
  • Reddit Find us on Reddit
Footer

AREAS OF EXPERTISE

  • Penetration Testing
  • Offensive Cybersecurity
  • Red Teaming
  • Compliance

IDENTITY SOLUTIONS

  • Access Assurance Suite
  • Core Password & Secure Reset
  • Core Privileged Access Manager (BoKS)

EXPERIENCE CORE

  • Watch our Core Impact Demo
  • Give Core Impact a Try
  • Compare Core Impact Pricing
  • Explore Core Impact Bundles & Suites

TOP RESOURCES

  • Must Read Blog
  • Must Read Research Article
  • Must Read Guide
  • Must Read Case Study
  • Must Watch Webinar

ABOUT

  • About Us
  • Partners
  • Careers
  • [email protected]

Privacy Policy

Cookie Policy

Terms of Service

Accessibility

Impressum

Copyright © Fortra, LLC and its group of companies. Fortra®, the Fortra® logos, and other identified marks are proprietary trademarks of Fortra, LLC.