mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-29 01:31:01 +00:00
18 lines
898 B
Markdown
18 lines
898 B
Markdown
![]() |
### [CVE-2018-2478](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-2478)
|
||
|
&color=blue)
|
||
|

|
||
|

|
||
|
|
||
|
### Description
|
||
|
|
||
|
An attacker can use specially crafted inputs to execute commands on the host of a TREX / BWA installation, SAP Basis, versions: 7.0 to 7.02, 7.10 to 7.11, 7.30, 7.31, 7.40 and 7.50 to 7.53. Not all commands are possible, only those that can be executed by the <sid>adm user. The commands executed depend upon the privileges of the <sid>adm user.
|
||
|
|
||
|
### POC
|
||
|
|
||
|
#### Reference
|
||
|
- https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=503809832
|
||
|
|
||
|
#### Github
|
||
|
No PoCs found on GitHub currently.
|
||
|
|