NA

CVE-2010-0368

Vulnerability Summary

Core Security Technologies Advisory - A security vulnerability exists in LANDesk Management Suite: a cross-site request forgery which allows an external remote malicious user to make a command injection that can be used to execute arbitrary code using the webserver user. As a result, an attacker can remove the firewall and load a kernel module, allowing root access to the appliance. It also can be used as a non-persistent XSS.

Exploits

source: wwwsecurityfocuscom/bid/38119/info LANDesk Management Gateway is prone to a cross-site request-forgery vulnerability and a cross-site scripting vulnerability An attacker can exploit the cross-site request forgery issue to alter the settings on affected devices This may lead to further network-based attacks, including command-in ...
Core Security Technologies Advisory - A security vulnerability was discovered in LANDesk Management Suite: a cross-site request forgery which allows an external remote attacker to make a command injection that can be used to execute arbitrary code using the webserver user As a result, an attacker can remove the firewall and load a kernel module, a ...