Watchguard XCS Remote Command Execution
Posted by deepcore on September 27, 2015 – 7:22 am
This Metasploit module exploits two separate vulnerabilities found in the Watchguard XCS virtual appliance to gain command execution. By exploiting an unauthenticated SQL injection, a remote attacker may insert a valid web user into the appliance database, and get access to the web interface. On the other hand, a vulnerability in the web interface allows the attacker to inject operating system commands as the ‘nobody’ user.
Post a reply
You must be logged in to post a comment.