Web Hack List

Collected research

CVE-2024-50603: Aviatrix Network Controller Command Injection Vulnerability

Analysis of CVE-2024-50603, an unauthenticated remote code execution flaw in Aviatrix Controller 7.x cloud networking appliances. A PHP wrapper around the controller's command-line tool applied escapeshellarg to most API parameters but omitted it on two, and the session identifier was only checked once the shell command had already run, so an anonymous HTTP POST could inject and execute an operating system command.

Record

Researcher
Jakub Korepta
Published by
Securing
Date
Format
Advisory
Topic
Injection

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Jakub Korepta, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .