Arbitrary Command Execution in Endian Firewall before 3.0 via chpasswd.cgi

Arbitrary Command Execution in Endian Firewall before 3.0 via chpasswd.cgi

CVE-2015-5082 · HIGH Severity

AV:N/AC:L/AU:N/C:C/I:C/A:C

Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW_PASSWORD_1 or (2) NEW_PASSWORD_2 parameter to cgi-bin/chpasswd.cgi.

Learn more about our Web Application Penetration Testing UK.