메뉴 건너뛰기

GREATUSER

cve

CVE-2017-16602

관리자 2018.01.25 04:00 조회 수 : 202

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.tools.exec_jsp servlet, which listens on TCP port 8081 by default. When parsing the command parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of Administrator. Was ZDI-CAN-5193.


원문출처 : https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2017-16602
번호 제목 글쓴이 날짜 조회 수
407 CVE-2017-13144 (imagemagick) 관리자 2017.08.27 186
406 CVE-2016-3198 관리자 2016.06.17 186
405 CVE-2017-13680 관리자 2017.11.09 185
404 CVE-2015-1395 관리자 2017.08.27 185
403 CVE-2017-5685 관리자 2017.04.04 185
402 CVE-2017-0057 관리자 2017.03.18 185
401 CVE-2017-0024 관리자 2017.03.18 185
400 CVE-2017-6555 (cms_made_simple) 관리자 2017.03.10 185
399 CVE-2017-1000416 관리자 2018.01.25 184
398 CVE-2018-5785 관리자 2018.01.25 184
397 CVE-2017-14031 관리자 2017.11.09 184
396 CVE-2017-12074 관리자 2017.08.27 184
395 CVE-2017-0112 관리자 2017.03.18 184
394 CVE-2016-0028 관리자 2016.06.17 184
393 CVE-2018-1000016 관리자 2018.01.25 183
위로