SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  OCS Inventory NG Remote Command Execution

Category: WEB-ATTACKS      

OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main_sections/ms_config/ms_snmp_config.php is mishandled in get_mib_oid.

References
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-14947


Relevant Information