CVE-2017-8051
21.04.2017, 18:59
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.
Vendor | Product | Version |
---|---|---|
tenable | appliance | 3.4.0 |
tenable | appliance | 3.5.0 |
tenable | appliance | 3.5.1 |
tenable | appliance | 3.10.0 |
tenable | appliance | 3.10.1 |
tenable | appliance | 4.0.0 |
tenable | appliance | 4.1.0 |
tenable | appliance | 4.2.0 |
tenable | appliance | 4.3.0 |
tenable | appliance | 4.3.1 |
tenable | appliance | 4.4.0 |
𝑥
= Vulnerable software versions