CVE-2010-2892
Last modified
CVE-2010-2892 is a vulnerability of currently unknown severity. gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.. EPSS estimates a 3.51% chance of exploitation in the next 30 days.
Description
gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Landesk | Management Gateway | 4.0 |
| Landesk | Management Gateway | 4.0-1.48 |
| Landesk | Management Gateway | 4.2 |
| Landesk | Management Gateway | 4.2-1.8 |
References
- http://community.landesk.com/support/docs/DOC-21767Vendor Advisory
- http://secunia.com/advisories/42188Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2957Vendor Advisory
- http://community.landesk.com/support/docs/DOC-21767Vendor Advisory
- http://secunia.com/advisories/42188Vendor Advisory
- http://www.vupen.com/english/advisories/2010/2957Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-2892?
How severe is CVE-2010-2892?
How do I fix CVE-2010-2892?
Are you affected by CVE-2010-2892?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
