Vulnerability Description
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Watchguard | Xcs | 9.2 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/132498/Watchguard-XCS-10.0-SQL-Injection-CoExploit
- http://packetstormsecurity.com/files/133721/Watchguard-XCS-Remote-Command-ExecutExploit
- http://www.rapid7.com/db/modules/exploit/freebsd/http/watchguard_cmd_exec
- http://www.security-assessment.com/files/documents/advisory/Watchguard-XCS-finalExploit
- http://www.securityfocus.com/bid/75516
- http://www.watchguard.com/support/release-notes/xcs/10/en-US/EN_Release_Notes_XCVendor Advisory
- http://www.watchguard.com/support/release-notes/xcs/9/en-US/EN_ReleaseNotes_XCS_Vendor Advisory
- https://www.exploit-db.com/exploits/38346/Exploit
- http://packetstormsecurity.com/files/132498/Watchguard-XCS-10.0-SQL-Injection-CoExploit
- http://packetstormsecurity.com/files/133721/Watchguard-XCS-Remote-Command-ExecutExploit
- http://www.rapid7.com/db/modules/exploit/freebsd/http/watchguard_cmd_exec
- http://www.security-assessment.com/files/documents/advisory/Watchguard-XCS-finalExploit
- http://www.securityfocus.com/bid/75516
- http://www.watchguard.com/support/release-notes/xcs/10/en-US/EN_Release_Notes_XCVendor Advisory
- http://www.watchguard.com/support/release-notes/xcs/9/en-US/EN_ReleaseNotes_XCS_Vendor Advisory
FAQ
What is CVE-2015-5453?
CVE-2015-5453 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl.
How severe is CVE-2015-5453?
CVE-2015-5453 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2015-5453?
Check the references section above for vendor advisories and patch information. Affected products include: Watchguard Xcs.