PT-2016-1727 · Xymon+1 · Xymon+1

Jccleaver

·

Publicado

2016-02-26

·

Atualizado

2018-10-09

·

CVE-2016-2056

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Xymon versions 4.1.x through 4.3.x before 4.3.25
Description The issue is related to the lack of input sanitization in the xymond component of the Xymon network monitoring tool. This allows a remote authenticated user to execute arbitrary commands by using shell metacharacters in the adduser name argument in either web/useradm.c or web/chpasswd.c.
Recommendations For Xymon versions 4.1.x through 4.3.x before 4.3.25, update to version 4.3.25 or later to resolve the issue.

Exploit

Correção

Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2016-1161
BDU:2016-01053
CVE-2016-2056
DLA-488-1
DSA-3495-1
MGASA-2016-0177

Produtos afetados

Alt Linux
Xymon