vendor:
ASOC 2200 Web Configurator
by:
Todor Donev
7.5
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: ASOC 2200 Web Configurator
Affected Version From: v2.6
Affected Version To: v2.6
Patch Exists: YES
Related CWE: N/A
CPE: h:acti:asoc_2200_web_configurator
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2011
ACTi ASOC 2200 Web Configurator <= v2.6 Remote Root Command Execution
ACTi Corporation is the technology leader in IP surveillance, focusing on multiple security surveillance market segments. This exploit allows an attacker to execute arbitrary commands on the vulnerable system with root privileges. The exploit is triggered by sending a specially crafted HTTP request to the vulnerable system.
Mitigation:
Upgrade to the latest version of ACTi ASOC 2200 Web Configurator