CVE-2010-2892: Input Validation
gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2892?
CVE-2010-2892 is considered a high severity vulnerability due to the potential for remote command execution.
How do I fix CVE-2010-2892?
To fix CVE-2010-2892, upgrade to a version of LANDesk Management Gateway that is not affected by this vulnerability.
What types of systems are affected by CVE-2010-2892?
CVE-2010-2892 affects LANDesk Management Gateway versions 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8.
Can CVE-2010-2892 be exploited remotely?
Yes, CVE-2010-2892 can be exploited remotely by authenticated administrators using cross-site request forgery techniques.
What impact does CVE-2010-2892 have on the affected systems?
CVE-2010-2892 allows attackers to execute arbitrary commands on the affected systems, which can lead to data breaches or system compromise.