vendor:
WiPG-1000
by:
Matthias Brun
N/A
CVSS
N/A
Command Injection
78
CWE
Product Name: WiPG-1000
Affected Version From: 2.0.0.7
Affected Version To: 2.2.3.0
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix
2017
WePresent WiPG-1000 Command Injection
This module exploits a command injection vulnerability in an undocumented CGI file in several versions of the WePresent WiPG-1000 devices. Version 2.0.0.7 was confirmed vulnerable, 2.2.3.0 patched this vulnerability.
Mitigation:
Upgrade to version 2.2.3.0 or later