Sophos Web Protection Appliance CVE-2013-2642 Multiple Command Injection Vulnerabilities
BID:58832
Info
Sophos Web Protection Appliance CVE-2013-2642 Multiple Command Injection Vulnerabilities
| Bugtraq ID: | 58832 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-2642 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 03 2013 12:00AM |
| Updated: | Apr 03 2013 12:00AM |
| Credit: | Wolfgang Ettlinger from SEC Consult Vulnerability Lab |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Sophos Web Protection Appliance CVE-2013-2642 Multiple Command Injection Vulnerabilities
Sophos Web Protection Appliance is prone to multiple command-injection vulnerabilities.
Attackers can exploit these issues to disclose sensitive information and execute arbitrary commands with the privileges of the 'spiderman' operating system user.
Web Protection Appliance 3.7.8.1 and prior versions are vulnerable.
Sophos Web Protection Appliance is prone to multiple command-injection vulnerabilities.
Attackers can exploit these issues to disclose sensitive information and execute arbitrary commands with the privileges of the 'spiderman' operating system user.
Web Protection Appliance 3.7.8.1 and prior versions are vulnerable.
Exploit / POC
Sophos Web Protection Appliance CVE-2013-2642 Multiple Command Injection Vulnerabilities
The following example data is available:
The following example data is available:
References
Sophos Web Protection Appliance CVE-2013-2642 Multiple Command Injection Vulnerabilities
References:
References: