Количество 2
Количество 2

CVE-2021-46704
больше 3 лет назад
In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check.
CVSS3: 9.8
EPSS: Высокий
GHSA-2877-693q-pj33
больше 3 лет назад
OS Command Injection in GenieACS
CVSS3: 9.8
EPSS: Высокий
Уязвимостей на страницу
20
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
![]() | CVE-2021-46704 In GenieACS 1.2.x before 1.2.8, the UI interface API is vulnerable to unauthenticated OS command injection via the ping host argument (lib/ui/api.ts and lib/ping.ts). The vulnerability arises from insufficient input validation combined with a missing authorization check. | CVSS3: 9.8 | 90% Высокий | больше 3 лет назад |
GHSA-2877-693q-pj33 OS Command Injection in GenieACS | CVSS3: 9.8 | 90% Высокий | больше 3 лет назад |
Уязвимостей на страницу
20