메뉴 건너뛰기

GREATUSER

cve

CVE-2017-16608

관리자 2018.01.25 04:00 조회 수 : 172

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within exec.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current user. Was ZDI-CAN-4749.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16608
번호 제목 글쓴이 날짜 조회 수
542 CVE-2017-13134 (imagemagick) 관리자 2017.08.27 100
541 CVE-2017-7326 관리자 2018.01.25 100
540 CVE-2017-6559 관리자 2017.03.10 101
539 CVE-2017-0113 관리자 2017.03.18 101
538 CVE-2017-11357 관리자 2017.08.27 101
537 CVE-2017-13658 (imagemagick) 관리자 2017.08.27 101
536 CVE-2017-12679 관리자 2017.08.27 101
535 CVE-2017-16563 관리자 2017.11.09 101
534 CVE-2017-0140 관리자 2017.03.18 102
533 CVE-2015-6473 (wago_i/o_plc_750-849_firmware, wago_i/o_plc_758-870_firmware) 관리자 2017.08.27 102
532 CVE-2017-12970 (apache2triad) 관리자 2017.08.27 102
531 CVE-2015-1801 관리자 2017.08.27 102
530 CVE-2017-12115 관리자 2018.01.25 103
529 CVE-2017-0128 관리자 2017.03.18 105
528 CVE-2017-0039 관리자 2017.03.18 106
위로