robertchrk/zmanda_exploit

robertchrk/zmanda_exploit

Releases0
Stars4
Weak default credentials in combination with missing input validation allow a remote attacker to execute arbitrary code on a server using the Zmanda Management Console 3.3.9.

CVE History

CVEPublishedCVSS v3CVSS v2
8.8 HIGH6.8 MEDIUM

In Zmanda Management Console 3.3.9, ZMC_Admin_Advanced?form=adminTasks&action=Apply&command= allows CSRF, as demonstrated by command injection with shell metacharacters. This may depend on weak default credentials.