Cisco Web Security Appliance CVE-2013-3383 Command Injection Vulnerability
BID:60804
Info
Cisco Web Security Appliance CVE-2013-3383 Command Injection Vulnerability
| Bugtraq ID: | 60804 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-3383 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2013 12:00AM |
| Updated: | Jun 26 2013 12:00AM |
| Credit: | Cisco |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Cisco Web Security Appliance CVE-2013-3383 Command Injection Vulnerability
Cisco Web Security Appliance is prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands with elevated privileges in context of the affected application.
This issue being tracked by Cisco bug ID CSCzv69294.
Versions prior to Cisco Web Security Appliance 7.1.3-013, 7.1.4-101, 7.5.0-838, and 7.7.0-550 are affected.
Cisco Web Security Appliance is prone to a remote command-injection vulnerability because it fails to properly sanitize user-supplied input.
Successfully exploiting this issue may allow an attacker to execute arbitrary commands with elevated privileges in context of the affected application.
This issue being tracked by Cisco bug ID CSCzv69294.
Versions prior to Cisco Web Security Appliance 7.1.3-013, 7.1.4-101, 7.5.0-838, and 7.7.0-550 are affected.
References
Cisco Web Security Appliance CVE-2013-3383 Command Injection Vulnerability
References:
References: