Description
OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters during connection configuration due to insufficient input validation.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Any version before 2.0.1
2.0.1 (custom)
Credits
Jacob Steadman, Rapid7
Jed Starr, Rapid7
References
extensions.rapid7.com/extension/sqlmap