Intellian Aptus Web 1.24 allows remote attackers to execute arbitrary OS commands via the Q field within JSON data to the cgi-bin/libagent.cgi URI. NOTE: a valid sid cookie for a login to the intellian default account might be needed.
References
Configurations
Information
Published : 2020-01-25 19:15
Updated : 2020-01-29 15:15
NVD link : CVE-2020-7980
Mitre link : CVE-2020-7980
JSON object : View
Products Affected
intelliantech
- aptus_web
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
