Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Aureliano Calvo

Researcher fromCore Security Technologies
#30811of 53,633
8.5Total CVSS
Vulnerabilities · 1
PT-2010-4383
8.5
2010-11-15
Landesk · Landesk Management Gateway · CVE-2010-2892
**Name of the Vulnerable Software and Affected Versions** LANDesk Management Gateway versions 4.0 through 4.0-1.48 LANDesk Management Gateway versions 4.2 through 4.2-1.8 **Description** The issue allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the `DRIVES` parameter. This can be demonstrated by a cross-site request forgery (CSRF) attack. **Recommendations** For versions 4.0 through 4.0-1.48, avoid using the `DRIVES` parameter in the gsb/drivers.php file until a patch is available. For versions 4.2 through 4.2-1.8, restrict access to the gsb/drivers.php file to minimize the risk of exploitation.