Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
LANDesk Management Gateway 'gsb/drivers.php'代码注入漏洞
Vulnerability Description
Landesk管理套件是一款网络管理系统,可控制桌面,服务器和移动设备等。 LANDesk Management Gateway 4.0至4.0-1.48版本以及4.2至4.2-1.8版本中的gsb/drivers.php文件中存在代码注入漏洞。远程认证管理员可以借助DRIVES参数中的shell元字符执行任意命令。该漏洞已经通过跨站伪造请求攻击得到证实。
CVSS Information
N/A
Vulnerability Type
N/A