The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote attackers to execute arbitrary commands via a DCP "run command" operation.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2013-01/0078.html | mailing list |
http://www.zerodayinitiative.com/advisories/ZDI-13-033/ | |
http://www.securityfocus.com/bid/57472 | vdb entry exploit |
http://www.exploit-db.com/exploits/34756 | exploit |