Vulnerabilities > Sophos > WEB Appliance Firmware > 3.2.6
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2014-04-11 | CVE-2014-2850 | OS Command Injection vulnerability in Sophos web Appliance and web Appliance Firmware The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter. | 8.5 |
2014-04-11 | CVE-2014-2849 | Permissions, Privileges, and Access Controls vulnerability in Sophos web Appliance and web Appliance Firmware The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request. | 8.5 |
2013-09-10 | CVE-2013-4983 | OS Command Injection vulnerability in Sophos web Appliance Firmware The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to end-user/index.php. | 10.0 |