CVE-2013-3632 EXPLOIT
8.8
HIGH · CVSS 3.1 · EPSS 57.1% (pctl 99)
Patch early
A public exploit exists.
Description
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.
Scoring
| CVSS | 8.8 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 57.11% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-264 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2014-09-29 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| openmediavault | openmediavault |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | OpenMediaVault Cron - Remote Command Execution (Metasploit) | 2013-10-31 |
References
- http://osvdb.org/99143
- http://www.exploit-db.com/exploits/29323
- http://www.securityfocus.com/bid/62873
- https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-foss-disclosures-part-one
- https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats
- http://osvdb.org/99143
- http://www.exploit-db.com/exploits/29323
- http://www.securityfocus.com/bid/62873
- https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-foss-disclosures-part-one
- https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats
- https://packetstormsecurity.com/files/179859
→ the Explorer · watch your stack · NVD