A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).
References
Link | Resource |
---|---|
http://packetstormsecurity.com/files/131284/Kemp-Load-Master-7.1-16-CSRF-XSS-DoS-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
https://www.exploit-db.com/exploits/36609/ | Exploit Third Party Advisory VDB Entry |
https://www.fxc.jp/news/Product_Overview-LoadMaster_Release_Notes.pdf | Release Notes Third Party Advisory |
http://packetstormsecurity.com/files/131284/Kemp-Load-Master-7.1-16-CSRF-XSS-DoS-Code-Execution.html | Exploit Third Party Advisory VDB Entry |
https://www.exploit-db.com/exploits/36609/ | Exploit Third Party Advisory VDB Entry |
https://www.fxc.jp/news/Product_Overview-LoadMaster_Release_Notes.pdf | Release Notes Third Party Advisory |
Configurations
History
21 Nov 2024, 02:11
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/131284/Kemp-Load-Master-7.1-16-CSRF-XSS-DoS-Code-Execution.html - Exploit, Third Party Advisory, VDB Entry | |
References | () https://www.exploit-db.com/exploits/36609/ - Exploit, Third Party Advisory, VDB Entry | |
References | () https://www.fxc.jp/news/Product_Overview-LoadMaster_Release_Notes.pdf - Release Notes, Third Party Advisory |
Information
Published : 2020-01-08 17:15
Updated : 2024-11-21 02:11
NVD link : CVE-2014-5287
Mitre link : CVE-2014-5287
CVE.ORG link : CVE-2014-5287
JSON object : View
Products Affected
kemptechnologies
- loadmaster
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')