The web module in Neteyes Nexusway allows remote attackers to execute arbitrary commands via hex-encoded shell metacharacters in the ip parameter for (1) nslookup.cgi or (2) ping.cgi.
Affected Software
Name |
Vendor |
Start Version |
End Version |
Nexusway |
Neteyes |
805 (including) |
805 (including) |
References