vendor:
OSSEC Manager
by:
Milad Saber
7.5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: OSSEC Manager
Affected Version From: 0.8
Affected Version To: 0.8
Patch Exists: YES
Related CWE: N/A
CPE: a:ossec:ossec_manager
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: OSSEC Manager
2015
[OSSEC]
This exploit allows an attacker to execute arbitrary code on an OSSEC server by sending a malicious payload via SMTP. The payload is sent to the server, which then executes it as root.
Mitigation:
Ensure that the OSSEC server is running the latest version and that all patches are up to date.