InfraPower PPS-02-S Q213V1 Unauthenticated Remote Root Command Execution

Discussion in 'News Aggregator' started by Packet Storm, 31 Oct 2016.

  1. Packet Storm

    Packet Storm Guest

    InfraPower PPS-02-S Q213V1 suffers from multiple unauthenticated remote command injection vulnerabilities. The vulnerability exists due to several POST parameters in several scripts not being sanitized when using the exec(), proc_open(), popen() and shell_exec() PHP function while updating the settings on the affected device. This allows the attacker to execute arbitrary system commands as the root user and bypass access controls in place.

    Continue reading...
     

Share This Page

Loading...