ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) prior to 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) count or (2) size parameter.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ibm global_console_manager_16_firmware |
||
ibm global_console_manager_32_firmware |