ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) count or (2) size parameter.
References
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 01:47
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.bitcloud.es/2013/08/vulnerabilidad-en-kvms-gcm1632-de-ibm.html - | |
References | () http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5093509 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/85367 - |
Information
Published : 2013-08-21 16:55
Updated : 2024-11-21 01:47
NVD link : CVE-2013-0526
Mitre link : CVE-2013-0526
CVE.ORG link : CVE-2013-0526
JSON object : View
Products Affected
ibm
- avocent_1754_kvm
- global_console_manager_16_firmware
- global_console_manager_32_firmware
CWE
CWE-20
Improper Input Validation