CVE-2014-5502 Information

Description

The Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote authenticated users to inject arbitrary commands via a (1) checkcert_key (2) webclient_portal_settings (3) sslvpn_liveuser_delete or (4) ccc_flush_sql_file opcode.

Reference

http://kb.cyberoam.com/default.asp?id=3049 http://www.zerodayinitiative.com/advisories/ZDI-14-328/ http://www.zerodayinitiative.com/advisories/ZDI-14-331/ http://www.zerodayinitiative.com/advisories/ZDI-14-332/ http://www.zerodayinitiative.com/advisories/ZDI-14-333/

Share on: