Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2017-8051

Disclosure Date: April 21, 2017 (last updated November 26, 2024)
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.
0
Attacker Value
Unknown

CVE-2014-2850

Disclosure Date: April 11, 2014 (last updated October 05, 2023)
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter.
0
Attacker Value
Unknown

CVE-2014-2849

Disclosure Date: April 11, 2014 (last updated October 05, 2023)
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.
0
Attacker Value
Unknown

CVE-2013-4984

Disclosure Date: September 10, 2013 (last updated October 05, 2023)
The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metacharacters in the second argument.
0
Attacker Value
Unknown

CVE-2013-4983

Disclosure Date: September 10, 2013 (last updated October 05, 2023)
The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to end-user/index.php.
0