PT-2013-4441 · Groundwork · Groundwork Monitor Enterprise
Publicado
2013-05-08
·
Atualizado
2013-05-08
·
CVE-2013-3506
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
GroundWork Monitor Enterprise version 6.7.0
Description
The issue is related to the improper restriction of XML content in the Performance component of GroundWork Monitor Enterprise. This allows remote attackers to execute arbitrary commands by creating a .shtml file and leveraging Server Side Includes (SSI) functionality.
Recommendations
For GroundWork Monitor Enterprise version 6.7.0, consider restricting access to the vulnerable
cgi-bin/performance/perfchart.cgi endpoint until a patch is available. As a temporary workaround, disabling Server Side Includes (SSI) functionality may help minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Groundwork Monitor Enterprise