PoC Index

CVE-2013-4094

MEDIUM 6.5EPSS 5.6%

The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to upload executable files via the (1) private_key or (2) public_key parameter in a T/keyManagement request to plain/settings.html, as demonstrated by uploading a Linux ELF file and a shell script.

CVSS v2.0
6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
EPSS
5.63% chance of exploitation in the next 30 days, 92th percentile
Published
2013-06-28
Updated
2024-09-17

ExploitDB entries (1)

References

Related