Sophos Web Appliance CVE-2013-4983 Remote Command Injection Vulnerability
BID:62263
Info
Sophos Web Appliance CVE-2013-4983 Remote Command Injection Vulnerability
| Bugtraq ID: | 62263 |
| Class: | Input Validation Error |
| CVE: |
CVE-2013-4983 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 06 2013 12:00AM |
| Updated: | Sep 18 2013 12:11AM |
| Credit: | Francisco Falcon from Core Exploit Writers Team |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Sophos Web Appliance CVE-2013-4983 Remote Command Injection Vulnerability
Sophos Web Appliance is prone to a remote command-injection vulnerability.
Attackers can exploit this issue to execute arbitrary commands with the privileges of the 'spiderman' operating system user.
Versions prior to Web Appliance 3.7.9.1 and 3.8.1.1 are vulnerable.
Sophos Web Appliance is prone to a remote command-injection vulnerability.
Attackers can exploit this issue to execute arbitrary commands with the privileges of the 'spiderman' operating system user.
Versions prior to Web Appliance 3.7.9.1 and 3.8.1.1 are vulnerable.
Exploit / POC
Sophos Web Appliance CVE-2013-4983 Remote Command Injection Vulnerability
The following exploit codes are available:
The following exploit codes are available:
Solution / Fix
Sophos Web Appliance CVE-2013-4983 Remote Command Injection Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Sophos Web Appliance CVE-2013-4983 Remote Command Injection Vulnerability
References:
References: