CVE-2018-16118

A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS commands via shell metachracters in the "X-Forwarded-for" HTTP header.
Configurations

Configuration 1


Information

Published : 2019-06-20 05:15

Updated : 2019-06-25 01:49


NVD link : CVE-2018-16118

Mitre link : CVE-2018-16118

Products Affected
No products.
CWE