9.3
CVSSv2

CVE-2013-2642

Published: 18/03/2014 Updated: 19/03/2014
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Sophos Web Appliance prior to 3.7.8.2 allows (1) remote malicious users to execute arbitrary commands via shell metacharacters in the client-ip parameter to the Block page, when using the user_workstation variable in a customized template, and remote authenticated users to execute arbitrary commands via shell metacharacters in the (2) url parameter to the Diagnostic Tools functionality or (3) entries parameter to the Local Site List functionality.

Vulnerable Product Search on Vulmon Subscribe to Product

sophos web_appliance_firmware

sophos web_appliance -

Exploits

SEC Consult Vulnerability Lab Security Advisory < 20130403-0 > ======================================================================= title: Multiple vulnerabilities product: Sophos Web Protection Appliance vulnerable version: <= 3781 fixed version: 3782 impact: Critical CVE num ...
Sophos Web Protection Appliance version 3781 suffers from OS command injection, cross site scripting, and file disclosure vulnerabilities ...