RULE(RULE ID:316502)

Rule General Information
Release Date: 2016-08-08
Rule Name: WEB-OTHER Endian Firewall Proxy Password Change Command Execution Vulnerability -2 (CVE-2015-5082)
Severity:
CVE ID:
Rule Protection Details
Description: Endian Firewall before 3.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) NEW_PASSWORD_1 or (2) NEW_PASSWORD_2 parameter to cgi-bin/chpasswd.cgi.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Network Device
Reference: ExploitDB:37426
ExploitDB:37428
ExploitDB:38096
Solutions
More advisories have been published on the website, please visit for more suggestions:
http://sourceforge.net/projects/efw/files/Development/EFW-3.0.0/