8.5
CVSSv2

CVE-2010-2892

Published: 15/11/2010 Updated: 10/10/2018
CVSS v2 Base Score: 8.5 | Impact Score: 10 | Exploitability Score: 6.8
VMScore: 855
Vector: AV:N/AC:M/Au:S/C:C/I:C/A:C

Vulnerability Summary

gsb/drivers.php in LANDesk Management Gateway 4.0 up to and including 4.0-1.48 and 4.2 up to and including 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.

Vulnerable Product Search on Vulmon Subscribe to Product

landesk management gateway 4.0-1.48

landesk management gateway 4.0

landesk management gateway 4.2-1.8

landesk management gateway 4.2

Exploits

1 Advisory Information Title: Landesk OS command injection Advisory Id: CORE-2010-1018 Advisory URL: wwwcoresecuritycom/content/landesk-os-command-injection-vulnerability Date published: 2010-11-10 Date of last update: 2010-11-10 Vendors contacted: LANDesk Release mode: Coordinated release 2 Vulnerability Information Class: OS command i ...
Core Security Technologies Advisory - A security vulnerability was discovered in LANDesk Management Suite: The Landesk web application does not sufficiently verify if a well-formed request was provided by the user who submitted the request Using this information an external remote attacker can run arbitrary code using the 'gsbadmin' user (that is ...