Within multiple XEROX products a vulnerability allows remote command execution on the Linux system, as the "nobody" user through a crafted "HTTP" request (OS Command Injection vulnerability in the HTTP interface). Depending upon configuration authentication may not be necessary.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: airbus
Published: 2019-04-12T17:37:54
Updated: 2024-08-04T22:32:02.151Z
Reserved: 2019-04-05T00:00:00
Link: CVE-2019-10880
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-04-12T18:29:01.177
Modified: 2024-11-21T04:20:02.213
Link: CVE-2019-10880
Redhat
No data.