NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnostic" page using the SnapMirror log path parameter.
The product imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
Link | Tags |
---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/84062 | vdb entry third party advisory |
https://www.securityfocus.com/archive/1/526552 | exploit vdb entry third party advisory |