TROYANOSYVIRUS
Volver a CVEs

CVE-2018-7739

N/A

Descripcion

antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and password parameters, as demonstrated by a username=>&password=%0a string to the /login URI. This allows obtaining root permissions within the web management console, because the login process uses Java's ProcessBuilder class and a bash script called antsle-auth with insufficient input validation.

Detalles CVE

Puntuacion CVSS v3.1N/A
Publicado3/7/2018
Ultima modificacion11/21/2024
Fuentenvd
Avistamientos honeypot0

Productos afectados

antsle:antman

Debilidades (CWE)

CWE-20

Correlaciones IOC

Sin correlaciones registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.