CVE-2018-15529
CVE-2018-15529
A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://packetstormsecurity.com/files/149065/Mutiny-Monitoring-Appliance-Command-Injection.htmlhttps://doddsecurity.com/135/remote-command-execution-on-the-monitoring-appliances/https://github.com/doddr/Security-Advisories/tree/master/Mutiny/CVE-2018-15529https://www.mutiny.com/mutiny-support/release-summary/