Логотип exploitDog
bind:CVE-2018-14417
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-14417

Количество 2

Количество 2

nvd логотип

CVE-2018-14417

больше 7 лет назад

A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-9m5c-7x86-6g8r

больше 3 лет назад

A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-14417

A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.

CVSS3: 9.8
72%
Высокий
больше 7 лет назад
github логотип
GHSA-9m5c-7x86-6g8r

A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.

CVSS3: 9.8
72%
Высокий
больше 3 лет назад

Уязвимостей на страницу