Release date:
Updated on:
Affected Systems:
Eaton Network Shutdown Module
Description:
--------------------------------------------------------------------------------
Bugtraq id: 54161
The Network Shutdown Module is a software used in the eaton mge office Protection System for secure Shutdown.
Network Shutdown Module 3.21 build 01 has a Remote PHP code execution vulnerability. Attackers can exploit this vulnerability to inject and execute malicious PHP code in Web server processes to control applications and lower-layer systems.
<* Source: Hans-Martin M & #195; & #188; nch
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Eaton
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://download.mgeops.com/explore/eng/network/net_sol.htm