CVE
- Id
- 96502
- CVE No.
- CVE-2016-9682
- Status
- Candidate
- Description
- The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system. The application doesn"t properly escape the information passed in the "tsrDeleteRestartedFile" or "currentTSREmailTo" variables before making a call to system(), allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.
- Phase
- Assigned (20161130)
- Votes
- None (candidate not yet proposed)
- Comments