Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-86h5-7c4r-g3gh

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the "second" parameter of a command, as demonstrated by the Destination parameter in the ping command.

The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the "second" parameter of a command, as demonstrated by the Destination parameter in the ping command.

EPSS

Процентиль: 97%
0.43909
Средний

Дефекты

CWE-77

Связанные уязвимости

nvd
почти 11 лет назад

The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the "second" parameter of a command, as demonstrated by the Destination parameter in the ping command.

EPSS

Процентиль: 97%
0.43909
Средний

Дефекты

CWE-77