Vulnerability record · CVE-2013-4983 · published 10 September 2013
CVE-2013-4983: Sophos Web Appliance command injection in sblistpack get_referers
Sophos · Web Appliance Firmware
The get_referers function in /opt/ws/bin/sblistpack on Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 passes the domain parameter from end-user/index.php to a shell without sanitizing shell metacharacters. A remote attacker can inject commands that execute with the privileges of the appliance process. Because the appliance sits inline on web traffic, compromise can expose or disrupt all proxied user activity.
Description
The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to end-user/index.php.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 10.0 with network reachability, no authentication, full command execution, public exploit references, and a very high EPSS score make this an urgent patch.
What it is
The get_referers function in /opt/ws/bin/sblistpack on Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 passes the domain parameter from end-user/index.php to a shell without sanitizing shell metacharacters. A remote attacker can inject commands that execute with the privileges of the appliance process. Because the appliance sits inline on web traffic, compromise can expose or disrupt all proxied user activity.
Impact
An unauthenticated remote attacker can execute arbitrary commands on the appliance, gaining full control of the device and any credentials or traffic it handles. This can lead to data theft, traffic manipulation, or use of the appliance as a pivot into the internal network.
Attack surface
Reachable over the network through end-user/index.php by supplying a crafted domain parameter; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required.
Exploitation
No CISA KEV listing and no ransomware association are recorded, but EPSS is 0.90133 (99.789th percentile) and the references include an Exploit-tagged Core Security advisory, indicating public exploit material exists and exploitation is likely.
What to do
- Upgrade Sophos Web Appliance to 3.7.9.1 or 3.8.1.1 (or later) as directed in Sophos knowledge base article 119773.
- If immediate patching is not possible, restrict network access to the end-user interface to trusted management networks only.
- Monitor and review the appliance for signs of compromise, and rotate any credentials or certificates stored on or passing through it.
- Apply input validation or a WAF rule blocking shell metacharacters in the domain parameter as a temporary compensating control.
Detection
- Inspect web and proxy logs for requests to end-user/index.php with shell metacharacters (;, |, &, $, backticks) in the domain parameter.
- Monitor appliance process execution for unexpected child processes spawned by sblistpack or the web server.
- Alert on outbound connections from the appliance to unfamiliar hosts, which may indicate command-and-control or data exfiltration.
- Review appliance and system logs for command execution errors or unusual activity around sblistpack.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2013-4983 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-4983), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.