vendor:
AKIPS Network Monitor
by:
BrianWGray
8,8
CVSS
HIGH
OS Command Injection
78
CWE
Product Name: AKIPS Network Monitor
Affected Version From: 15.37
Affected Version To: 16.5
Patch Exists: YES
Related CWE: N/A
CPE: a:akips:akips_network_monitor
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: FreeBSD 10.2-RELEASE-p7
2016
AKIPS Network Monitor 15.37-16.6 OS Command Injection
The 'username' login parameter allows for OS Command injection via command Injection during a failed login attempt returns the command injection output to a limited login failure field. By using concatenation '||' a command may be appended to the username.
Mitigation:
Update to version 16.6