CVE-2013-4094
28.06.2013, 23:55
The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to upload executable files via the (1) private_key or (2) public_key parameter in a T/keyManagement request to plain/settings.html, as demonstrated by uploading a Linux ELF file and a shell script.Enginsight
Vendor | Product | Version |
---|---|---|
imperva | securesphere | 9.0.0.5 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References