Lantronix xPrintServer does not properly restrict access to ips/, which allows remote attackers to execute arbitrary commands via the c parameter in an rpc action.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://seclists.org/fulldisclosure/2014/Nov/24 | mailing list exploit |
http://packetstormsecurity.com/files/129091/Lantronix-xPrintServer-Remote-Command-Execution-CSRF.html | exploit |
http://i.imgur.com/gjbZhXZ.png | exploit |
https://exchange.xforce.ibmcloud.com/vulnerabilities/98644 | vdb entry |