Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Aureliano Calvo

Pesquisador deCore Security Technologies
#30811de 53,635
8.5CVSS total
Vulnerabilidades · 1
PT-2010-4383
8.5
2010-11-15
Landesk · Landesk Management Gateway · CVE-2010-2892
**Name of the Vulnerable Software and Affected Versions** LANDesk Management Gateway versions 4.0 through 4.0-1.48 LANDesk Management Gateway versions 4.2 through 4.2-1.8 **Description** The issue allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the `DRIVES` parameter. This can be demonstrated by a cross-site request forgery (CSRF) attack. **Recommendations** For versions 4.0 through 4.0-1.48, avoid using the `DRIVES` parameter in the gsb/drivers.php file until a patch is available. For versions 4.2 through 4.2-1.8, restrict access to the gsb/drivers.php file to minimize the risk of exploitation.