Kerio Control Remote Command Execution Vulnerability
Description
(:A vulnerability has been identified in Kerio Control.:A remote attacker with admin privileges could exploit it by uploading an upgrade.sh shell script inside a tar archive renamed with .img extension in order to execute arbitrary commands with root privileges.::The exploitation of this vulnerability can be combined with a cross-site request forgery attack by inciting an admin into opening a malicious link triggering the vulnerable feature.::A proof of concept exists.)