Remote Command Injection Vulnerability in Sophos Web Appliance
CVE-2016-9553
What is CVE-2016-9553?
The Sophos Web Appliance is affected by a Remote Command Injection vulnerability within its web administrative interface. Specifically, two vulnerabilities exist in the MgrReport.php component, which handles the blocking and unblocking of IP addresses. The system fails to properly sanitize user inputs from the 'unblockip' and 'blockip' variables before executing them via the shell_exec() function. This oversight allows attackers to inject arbitrary commands into the system. Although the variable name 'escapedips' implies some level of protection, the actual implementation is flawed, exposing the device to exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
EPSS Score
6% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
