CRITICAL🇵🇱 Wersja polska

CVE-2017-17407

CVSS 9.8v3.0pub. 2018-01-23upd. 2024-11-21

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager v7.2.699 build 1001. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the content parameter provided to the script_test.jsp endpoint. A crafted content request parameter can trigger execution of a system call composed from a user-supplied string. An attacker can leverage this vulnerability to execute code under the context of the web service. Was ZDI-CAN-5080.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Netgain Systems Enterprise Manager

    APP
    Netgain-Systems
    7.2.699
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCECommand Injection
CWE
References

Related vulnerabilities

CVE-2017-16610CRITICAL9.8PL ✓same product

RCE przez path traversal w Netgain Enterprise Manager (upload_save_do.jsp)

CVE-2017-17406CRITICAL9.8PL ✓same product

RCE przez deserializację w Netgain Enterprise Manager (RMI)

CVE-2017-16608CRITICAL9.8PL ✓same product

RCE bez uwierzytelnienia w Netgain Enterprise Manager (exec.jsp)

CVE-2017-16597CRITICAL9.8PL ✓same product

RCE poprzez path traversal w NetGain Systems Enterprise Manager

CVE-2018-10587HIGH7.2same product

NetGain Enterprise Manager (EM) is affected by OS Command Injection vulnerabilities in versions before 10.0.57...