ID:1375 - Exploit for OS command injection in OfficeScan - CVE-2017-11394

 
Main Vulnerability Database Exploits ID:1375 - Exploit for OS command injection in OfficeScan - CVE-2017-11394

ID:1375 - Exploit for OS command injection in OfficeScan - CVE-2017-11394

Published: March 18, 2020


Vulnerability identifier: #VU9344
Vulnerability risk: High
CVE-ID: CVE-2017-11394
CWE-ID: CWE-78
Exploitation vector: Remote access
Vulnerable software:
OfficeScan

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to execute arbitrary system commands on the target system.

The vulnerability exists due to insufficient filtration of user-supplied data passed via the "T" parameter to Proxy.php script. A remote unauthenticated attacker can execute arbitrary commands on the affected system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Remediation

Install updates form vendor's website: