Sophos Web Appliance MgrReport blocking Vulnerablity Remote Code Execution Exploit

A vulnerability exists in the MgrReport.php (/controllers/MgrReport.php) component responsible for blocking and unblocking IP addresses from accessing the device.



By abusing the blockip variable, an attacker can achieve remote code execution.
Exploit Type - Old
Exploits/Remote
Exploit Platform
Exploit Type
Product Name