Record summary

CVE-2010-2892 has a selected CVSS score of 8.5; EIP currently links 1 catalogued exploit.

Description

gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBLandesk - OS command InjectionExploitDB exploitby Aureliano CalvoNot analyzed1 file
ExploitDB

PoC details

References

9