Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Remote Code Execution in Micro Focus Secure Messaging Gateway
Vulnerability Description
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with CVE-2018-12464 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that used GWAVA product name (i.e. GWAVA 6.5).
CVSS Information
N/A
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
Micro Focus Secure Messaging Gateway Web administration组件操作系统命令注入漏洞
Vulnerability Description
Micro Focus Secure Messaging Gateway(SMG)是英国Micro Focus公司的一套企业网络和消息系统出、入站保护软件。该产品包括病毒防护、反垃圾邮件、防DDos攻击和图像分析等功能。Web administration是其中的一个基于Web的管理组件。 Micro Focus SMG 471之前版本中的Web administration组件存在操作系统命令注入漏洞。远程攻击者可利用该漏洞在SMG服务器上执行任意的操作系统命令。
CVSS Information
N/A
Vulnerability Type
N/A