Beveiligingsadvies

CVE-2012-10048

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-08-08 18:14:38
Laatst bijgewerkt 2026-04-07 14:02:42
Toegewezen door VulnCheck
CVSS-score 8.7
Status PUBLISHED

Beschrijving

Zenoss Core 3.x contains a command injection vulnerability in the showDaemonXMLConfig endpoint. The daemon parameter is passed directly to a Popen() call in ZenossInfo.py without proper sanitation, allowing authenticated users to execute arbitrary commands on the server as the zenoss user.