masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and previous versions allows remote malicious users to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
alcatel-lucent omnipcx 7.1 |