A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload.
References
Configurations
History
21 Nov 2024, 03:51
Type | Values Removed | Values Added |
---|---|---|
References | () http://packetstormsecurity.com/files/149065/Mutiny-Monitoring-Appliance-Command-Injection.html - Third Party Advisory, VDB Entry | |
References | () https://doddsecurity.com/135/remote-command-execution-on-the-monitoring-appliances/ - | |
References | () https://github.com/doddr/Security-Advisories/tree/master/Mutiny/CVE-2018-15529 - Third Party Advisory | |
References | () https://www.mutiny.com/mutiny-support/release-summary/ - |
Information
Published : 2018-08-28 17:29
Updated : 2024-11-21 03:51
NVD link : CVE-2018-15529
Mitre link : CVE-2018-15529
CVE.ORG link : CVE-2018-15529
JSON object : View
Products Affected
mutiny
- mutiny
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')