Описание
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2013-3632
- https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-foss-disclosures-part-one
- https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats
- https://packetstormsecurity.com/files/179859
- http://osvdb.org/99143
- http://www.exploit-db.com/exploits/29323
- http://www.securityfocus.com/bid/62873
Связанные уязвимости
CVSS3: 8.8
nvd
больше 11 лет назад
The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.