masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
References
Configurations
Configuration 1 (hide)
|
History
07 Feb 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-77 |
Information
Published : 2007-09-18 21:17
Updated : 2025-04-09 00:30
NVD link : CVE-2007-3010
Mitre link : CVE-2007-3010
CVE.ORG link : CVE-2007-3010
JSON object : View
Products Affected
al-enterprise
- omnipcx_enterprise_communication_server
CWE
NVD-CWE-noinfo
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')