Zen Load Balancer 3.10.1 allows remote authenticated admin users to execute arbitrary commands as root via shell metacharacters in the index.cgi?action=View_Cert certname parameter.
References
Link | Resource |
---|---|
https://code610.blogspot.com/2019/01/rce-in-zenload-balancer.html | Exploit Third Party Advisory |
http://www.securityfocus.com/bid/106812 | Third Party Advisory |
Configurations
Information
Published : 2019-02-01 01:29
Updated : 2020-08-24 10:37
NVD link : CVE-2019-7301
Mitre link : CVE-2019-7301
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
zevenet
- zen_load_balancer