NetGain Enterprise Manager (EM) is affected by OS Command Injection vulnerabilities in versions before 10.0.57. These vulnerabilities could allow remote authenticated attackers to inject arbitrary code, resulting in remote code execution.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HNetgain Systems Enterprise Manager
APPNetgain-Systems< 10.0.57
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCECommand Injection
CWE
Related vulnerabilities
CVE-2017-16610CRITICAL9.8PL ✓same product
RCE przez path traversal w Netgain Enterprise Manager (upload_save_do.jsp)
CVE-2017-17406CRITICAL9.8PL ✓same product
RCE przez deserializację w Netgain Enterprise Manager (RMI)
CVE-2017-16608CRITICAL9.8PL ✓same product
RCE bez uwierzytelnienia w Netgain Enterprise Manager (exec.jsp)
CVE-2017-16597CRITICAL9.8PL ✓same product
RCE poprzez path traversal w NetGain Systems Enterprise Manager
CVE-2017-17407CRITICAL9.8PL ✓same product
RCE bez uwierzytelnienia w NetGain Systems Enterprise Manager (script_test.jsp)