Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system. The application doesn't properly escape the information passed in the 'tsrDeleteRestartedFile' or 'currentTSREmailTo' variables before making a call to system(), allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Dell SonicWall Secure Remote Access服务器命令注入漏洞
Vulnerability Description
Dell SonicWall Secure Remote Access(SRA)是美国戴尔(Dell)公司的一款Dell SonicWall安全移动访问解决方案中的SonicWALL安全远程访问系列设备。 Dell SonicWall SRA服务器8.1.0.2-14sv版本中的Web管理界面的diagnostics CGI (/cgi-bin/diagnostics)组件存在远程命令注入漏洞。攻击者可利用该漏洞获取远程设备的shell访问权限。
CVSS Information
N/A
Vulnerability Type
N/A