6.8
CVSSv2

CVE-2010-4099

Published: 27/10/2010 Updated: 17/08/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 690
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

ess.pm in NitroSecurity NitroView ESM 8.4.0a, when ESSPMDebug is enabled, allows remote malicious users to execute arbitrary commands via shell metacharacters in the Request parameter to ess.

Vulnerable Product Search on Vulmon Subscribe to Product

nitrosecurity nitroview_esm_software 8.4.0a

Exploits

-- Product description: NitroView ESM is an enterprise-class security information and event management system that identifies, correlates, and remediates threats faster than any other SIEM on the market -- Problem Description: During research it was found that perl module "esspm" is prone to remote code execution vulnerability due to lack of use ...
source: wwwsecurityfocuscom/bid/44421/info NitroView ESM is prone to a remote command-execution vulnerability because it fails to adequately sanitize user-supplied input Successful attacks may allow an attacker to execute arbitrary commands on the appliance in the context of the webserver process NitroView ESM 840a is affected; othe ...