Command Injection in froxlor/froxlor
78Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 7.2epss 98%
from disclosure to weapon13 days
Published on NVDJan 16
1st PoC+13d
metasploit+13d
exploitation probability
98%top 1% of all CVEs
observed exploitation
nono source reports it
4 public exploit(s)
Command Injection in GitHub repository froxlor/froxlor prior to 2.0.8.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
froxlor · froxlor/froxlorpublic PoCs found — 4
exploitdbwww.exploit-db.com/exploits/51263unverifiedgithubgithub.com/mhaskar/CVE-2023-0315★ 7cve_referencepacketstormsecurity.com/files/171108/Froxlor-2.0.6-Remote-Command-Execution.htmlunverifiedcve_referencepacketstormsecurity.com/files/171729/Froxlor-2.0.3-Stable-Remote-Code-Execution.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://packetstormsecurity.com/files/171108/Froxlor-2.0.6-Remote-Command-Execution.htmlhttp://packetstormsecurity.com/files/171729/Froxlor-2.0.3-Stable-Remote-Code-Execution.htmlhttps://github.com/froxlor/froxlor/commit/090cfc26f2722ac3036cc7fd1861955bc36f065ahttps://huntr.dev/bounties/ff4e177b-ba48-4913-bbfa-ab8ce0db5943