vendor:
GestioIP
by:
bperry
N/A
CVSS
N/A
Command Injection
78
CWE
Product Name: GestioIP
Affected Version From: 3.0
Affected Version To: 3.0
Patch Exists: YES
Related CWE: N/A
CPE: a:gestioip:gestioip:3.0
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Unix
2013
GestioIP Remote Command Execution
This module exploits a command injection flaw to create a shell script on the filesystem and execute it. If GestioIP is configured to use no authentication, no password is required to exploit the vulnerability. Otherwise, an authenticated user is required to exploit.
Mitigation:
Patch the vulnerable version of GestioIP with the patch provided by the vendor.