SonicALERT
Search

Sonicwall Signatures

 

Go to All Categories list.


  Eveo URVE Web Manager OS Command Injection

Category: WEB-ATTACKS      

An issue was discovered in Eveo URVE Web Manager 27.02.2025. The application exposes a /_internal/pc/vpro.php localhost endpoint to unauthenticated users that is vulnerable to OS Command Injection. The endpoint takes an input parameter that is passed directly into the shell_exec function of PHP.


Relevant Information