RSS   Vulnerabilities for 'Secure web gateway'   RSS

2017-12-31
 
CVE-2017-18001

CWE-306
 

 
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI.

 

 >>> Vendor: Trustwave 5 Products
Webdefend
Secure web gateway
Owasp modsecurity core rule set
Modsecurity
Mailmarshal


Copyright 2024, cxsecurity.com

 

Back to Top