The web module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via hex-encoded shell metacharacters in the ip parameter for (1) nslookup.cgi or (2) ping.cgi.
Link | Tags |
---|---|
http://secunia.com/advisories/15150 | exploit third party advisory patch vendor advisory |
http://marc.info/?l=bugtraq&m=111585017832066&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/20557 | vdb entry |
http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/033945.html | mailing list exploit vendor advisory |
http://www.osvdb.org/16449 | vdb entry vendor advisory |
http://www.osvdb.org/16448 | vdb entry vendor advisory |