Watchguard XCS Remote Command Execution...

- AV AC AU C I A
发布: 2015-09-26
修订: 2025-04-13

This Metasploit module exploits two separate vulnerabilities found in the Watchguard XCS virtual appliance to gain command execution. By exploiting an unauthenticated SQL injection, a remote attacker may insert a valid web user into the appliance database, and get access to the web interface. On the other hand, a vulnerability in the web interface allows the attacker to inject operating system commands as the 'nobody' user.

0%
当前有1条漏洞利用/PoC
当前有0条受影响产品信息