VendorsSophosweb_appliance_firmware3.7.9.1
Vulnerabilities

Sophos Web Appliance firmware 3.7.9.1

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2014-2849
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users to change the admin user password via a crafted request.
Published 2014-04-11 · Modified
8.51 PoCEPSS 0.603
CVE-2014-2850
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrators to execute arbitrary commands via shell metacharacters in the address parameter.
Published 2014-04-11 · Modified
8.51 PoCEPSS 0.577