NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.
oryginał ENCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HNedi
APPNedi1.9c
Powiązane podatności
NeDi — User Enumeration w formularzu logowania i resetowania hasła
NeDi 1.9C — wstrzyknięcie kodu PHP przez uwierzytelnionego użytkownika
NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the en...
NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a ...
NeDi 1.9C is vulnerable to Remote Command Execution. System-Snapshot.php improperly escapes shell metacharacte...