Beveiligingsadvies

CVE-2007-3572

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2007-07-05 20:00:00
Laatst bijgewerkt 2024-08-07 14:21:36
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Incomplete blacklist vulnerability in cgi-bin/runDiagnostics.cgi in the web interface on the Yoggie Pico and Pico Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the param parameter, as demonstrated by URL encoded "`" (backtick) characters (%60 sequences).