Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the device.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Xerox
Subscribe
|
Workcentre 3655
Subscribe
Workcentre 3655 Firmware
Subscribe
Workcentre 3655i
Subscribe
Workcentre 3655i Firmware
Subscribe
Workcentre 5865
Subscribe
Workcentre 5865 Firmware
Subscribe
Workcentre 5865i
Subscribe
Workcentre 5865i Firmware
Subscribe
Workcentre 5875
Subscribe
Workcentre 5875 Firmware
Subscribe
Workcentre 5875i
Subscribe
Workcentre 5875i Firmware
Subscribe
Workcentre 5890
Subscribe
Workcentre 5890 Firmware
Subscribe
Workcentre 5890i
Subscribe
Workcentre 5890i Firmware
Subscribe
Workcentre 5945
Subscribe
Workcentre 5945 Firmware
Subscribe
Workcentre 5945i
Subscribe
Workcentre 5945i Firmware
Subscribe
Workcentre 5955
Subscribe
Workcentre 5955 Firmware
Subscribe
Workcentre 5955i
Subscribe
Workcentre 5955i Firmware
Subscribe
Workcentre 6655
Subscribe
Workcentre 6655 Firmware
Subscribe
Workcentre 6655i
Subscribe
Workcentre 6655i Firmware
Subscribe
Workcentre 7200
Subscribe
Workcentre 7200 Firmware
Subscribe
Workcentre 7200i
Subscribe
Workcentre 7200i Firmware
Subscribe
Workcentre 7220
Subscribe
Workcentre 7220 Firmware
Subscribe
Workcentre 7225
Subscribe
Workcentre 7225 Firmware
Subscribe
Workcentre 7225i
Subscribe
Workcentre 7225i Firmware
Subscribe
Workcentre 7830
Subscribe
Workcentre 7830 Firmware
Subscribe
Workcentre 7835
Subscribe
Workcentre 7835 Firmware
Subscribe
Workcentre 7845
Subscribe
Workcentre 7845 Firmware
Subscribe
Workcentre 7855
Subscribe
Workcentre 7855 Firmware
Subscribe
Workcentre 7970
Subscribe
Workcentre 7970 Firmware
Subscribe
Workcentre 7970i
Subscribe
Workcentre 7970i Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-2050 | Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, and 7970i devices before 073.xxx.086.15410 do not properly escape parameters in the support/remoteUI/configrui.php script, which can allow an unauthenticated attacker to execute OS commands on the device. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T03:47:34.938Z
Reserved: 2020-04-29T00:00:00.000Z
Link: CVE-2016-11061
No data.
Status : Modified
Published: 2020-04-29T22:15:11.810
Modified: 2024-11-21T02:45:24.550
Link: CVE-2016-11061
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD