← All CVEs

CVE-2015-2746

medium · 6.5

The network diagnostics tool (CommandLineServlet) in the Appliance Manager command line utility (CLU) in Websense TRITON 7.8.3 and V-Series appliances before 7.8.4 Hotfix 02 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the "second" parameter of a command, as demonstrated by the Destination parameter in the ping command.

6.5
CVSS
25.4%
EPSS (exploit prob.)
98th
EPSS percentile
2015-03-26
Published

AV:N/AC:L/Au:S/C:P/I:P/A:P

Weaknesses

CWE-77

Affected products

VendorProductAffected versions
websensetriton7.8.3
websensev-series_appliances<= 7.7

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2015-2746