CVE-2010-2892
LANDesk Management Gateway <4.0-1.48 & <4.2-1.8 - Command Injection
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2010-2892. PoCs published by Aureliano Calvo.
AI-analyzed exploit summary This exploit demonstrates an OS command injection vulnerability in LANDesk Management Suite's web application. It allows arbitrary command execution via the 'DRIVES' parameter in a POST request to 'drivers.php', leveraging the gsbadmin user's sudo privileges.
Description
gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.
Exploits (1)
This exploit demonstrates an OS command injection vulnerability in LANDesk Management Suite's web application. It allows arbitrary command execution via the 'DRIVES' parameter in a POST request to 'drivers.php', leveraging the gsbadmin user's sudo privileges.