Landesk · Landesk Management Gateway · CVE-2010-2892
**Name of the Vulnerable Software and Affected Versions**
LANDesk Management Gateway versions 4.0 through 4.0-1.48
LANDesk Management Gateway versions 4.2 through 4.2-1.8
**Description**
The issue allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the `DRIVES` parameter. This can be demonstrated by a cross-site request forgery (CSRF) attack.
**Recommendations**
For versions 4.0 through 4.0-1.48, avoid using the `DRIVES` parameter in the gsb/drivers.php file until a patch is available.
For versions 4.2 through 4.2-1.8, restrict access to the gsb/drivers.php file to minimize the risk of exploitation.