Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j542-2x58-5jg4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.

EPSS

Процентиль: 100%
0.93438
Критический

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

TerraMaster TOS before 4.1.29 has Invalid Parameter Checking that leads to code injection as root. This is a dynamic class method invocation vulnerability in include/exportUser.php, in which an attacker can trigger a call to the exec method with (for example) OS commands in the opt parameter.

EPSS

Процентиль: 100%
0.93438
Критический

Дефекты

CWE-78