Security Advisory

CVE-2017-9757

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-06-19 13:00:00
Last updated 2024-08-05 17:18:01
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

IPFire 2.19 has a Remote Command Injection vulnerability in ids.cgi via the OINKCODE parameter, which is mishandled by a shell. This can be exploited directly by authenticated users, or through CSRF.