메뉴 건너뛰기

GREATUSER

cve

CVE-2017-16608

관리자 2018.01.25 04:00 조회 수 : 172

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Netgain Enterprise Manager. Authentication is not required to exploit this vulnerability. The specific flaw exists within exec.jsp. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current user. Was ZDI-CAN-4749.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16608
번호 제목 글쓴이 날짜 조회 수
497 CVE-2016-6310 관리자 2017.08.27 119
496 CVE-2015-3617 관리자 2017.08.27 120
495 CVE-2017-14121 관리자 2017.09.04 120
494 CVE-2017-12847 관리자 2017.08.27 121
493 CVE-2017-16641 관리자 2017.11.09 121
492 CVE-2016-4460 관리자 2017.08.27 122
491 CVE-2015-7896 관리자 2017.08.27 122
490 CVE-2017-16649 관리자 2017.11.09 123
489 CVE-2017-11317 관리자 2017.08.27 124
488 CVE-2017-12879 관리자 2017.08.27 124
487 CVE-2015-8308 관리자 2017.08.27 124
486 CVE-2017-1693 관리자 2018.01.25 124
485 CVE-2017-5642 관리자 2017.04.04 125
484 CVE-2017-12836 관리자 2017.08.27 125
483 CVE-2017-14082 관리자 2018.01.25 125
위로