CVE-2015-5082
28.09.2015, 15:59
Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW_PASSWORD_1 or (2) NEW_PASSWORD_2 parameter to cgi-bin/chpasswd.cgi.
Vendor | Product | Version |
---|---|---|
endian_firewall | endian_firewall | 𝑥 ≤ 2.5.1 |
𝑥
= Vulnerable software versions
References