HIGH🇬🇧 English

CVE-2021-26752

CVSS 8.8v3.1pub. 2021-02-12upd. 2024-11-21

NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Nedi

    APP
    Nedi
    1.9c
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Command Injection
CWE
Referencje

Powiązane podatności

CVE-2022-40895CRITICAL9.1PL ✓ten sam produkt

NeDi — User Enumeration w formularzu logowania i resetowania hasła

CVE-2021-26753CRITICAL9.9PL ✓ten sam produkt

NeDi 1.9C — wstrzyknięcie kodu PHP przez uwierzytelnionego użytkownika

CVE-2021-26751HIGH8.8ten sam produkt

NeDi 1.9C allows an authenticated user to perform a SQL Injection in the Monitoring History function on the en...

CVE-2020-14414HIGH8.8ten sam produkt

NeDi 1.9C is vulnerable to Remote Command Execution. pwsec.php improperly escapes shell metacharacters from a ...

CVE-2020-14412HIGH8.8ten sam produkt

NeDi 1.9C is vulnerable to Remote Command Execution. System-Snapshot.php improperly escapes shell metacharacte...