The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitrary commands via a modified request to the LSRoom_Remoting.doCommand function in gateway.php.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/69444 | vdb entry |
http://www.exploit-db.com/exploits/17743 | exploit |
http://securityreason.com/securityalert/8527 | third party advisory |
http://www.securityfocus.com/bid/49330 | vdb entry exploit |
http://www.securityfocus.com/archive/1/519463/100/0/threaded | mailing list |
http://www.kb.cert.org/vuls/id/213486 | third party advisory us government resource |
http://www.securestate.com/Documents/LifeSize_Room_Advisory.txt | exploit |
http://securityreason.com/securityalert/8363 | third party advisory |