SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Tenable Appliance simpleupload.py Command Injection

Category: WEB-ATTACKS      

Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.


Relevant Information