CVE
- Id
- 96504
- CVE No.
- CVE-2016-9684
- Status
- Candidate
- Description
- The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the "viewcert" CGI (/cgi-bin/viewcert) component responsible for processing SSL certificate information. The CGI application doesn"t properly escape the information it"s passed in the "CERT" variable before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.
- Phase
- Assigned (20161130)
- Votes
- None (candidate not yet proposed)
- Comments