CVE-2010-2892
15.11.2010, 21:00
gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.Enginsight
Vendor | Product | Version |
---|---|---|
landesk | management_gateway | 4.0 |
landesk | management_gateway | 4.0-1.48 |
landesk | management_gateway | 4.2 |
landesk | management_gateway | 4.2-1.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References