CVE-2013-3506: Gwos Groundwork Monitor
High severity, CVSS 7.5. EPSS: 2.5% chance of exploitation in the next 30 days.
cgi-bin/performance/perfchart.cgi in the Performance component in GroundWork Monitor Enterprise 6.7.0 does not properly restrict XML content, which allows remote attackers to execute arbitrary commands by creating a .shtml file and leveraging Server Side Includes (SSI) functionality.
Affected products
- Gwos Groundwork Monitor: version 6.7.0 only
Published 2013-05-08. Last modified 2026-06-16.