mirror of
https://github.com/0xMarcio/cve.git
synced 2025-06-19 17:30:12 +00:00
18 lines
941 B
Markdown
18 lines
941 B
Markdown
### [CVE-2015-7828](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7828)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
SAP HANA Database 1.00 SPS10 and earlier do not require authentication, which allows remote attackers to execute arbitrary code or have unspecified other impact via a TrexNet packet to the (1) fcopydir, (2) fmkdir, (3) frmdir, (4) getenv, (5) dumpenv, (6) fcopy, (7) fput, (8) fdel, (9) fmove, (10) fget, (11) fappend, (12) fdir, (13) getTraces, (14) kill, (15) pexec, (16) stop, or (17) pythonexec method, aka SAP Security Note 2165583.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- http://packetstormsecurity.com/files/134281/SAP-HANA-TrexNet-Command-Execution.html
|
|
|
|
#### Github
|
|
No PoCs found on GitHub currently.
|
|
|