CVE-2014-2850 | Sophos Web Appliance up to 3.7.7 address os command injection (EDB-32789 / BID-66734)
A vulnerability was found in Sophos Web Appliance up to 3.7.7. It has been classified as critical. Affected is an unknown function. The manipulation of the argument address leads to os command injection.
This vulnerability is traded as CVE-2014-2850. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.