vendor:
eScan Antivirus
by:
Mohammed almutairi
7.5
CVSS
HIGH
Remote Command Execution
CWE
Product Name: eScan Antivirus
Affected Version From: 3.x
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Linux
MicroWorld eScan Antivirus Remote Root Command Execution
The vulnerability exists in the forgotpassword.php file of MicroWorld eScan Antivirus < 3.x on Linux. The script does not properly validate user input in the 'uname' parameter, allowing an attacker to inject malicious commands and execute them with root privileges. By sending a specially crafted POST request to the forgotpassword.php script, an attacker can execute arbitrary commands on the target system.
Mitigation:
Update to the latest version of MicroWorld eScan Antivirus.