bitcloud.es
http://www.bitcloud.es/2013/08/vulnerabilidad-en-kvms-gcm1632-de-ibm.html CVE-2013-0526
IBM 1754 GCM 1.18.0.22011 - Remote Command Execution
Record summary
CVE-2013-0526 has a selected CVSS score of 8.5; EIP currently links 1 catalogued exploit.
Description
ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) count or (2) size parameter.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBIBM 1754 GCM 1.18.0.22011 - Remote Command ExecutionExploitDB exploitby Alejandro Alvarez BravoNot analyzed1 file
References
4ibm.comConfirmation
http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5093509 gcm-cve20130526-command-exec(85367)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/85367 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-0526