An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command execution.
This Cyber News was published on www.tenable.com. Publication date: Wed, 15 Jan 2025 14:56:01 +0000