Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2026-38822

17 дней назад

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.

CVSS3: 7.6
EPSS: Низкий
nvd логотип

CVE-2026-38822

17 дней назад

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.

CVSS3: 7.6
EPSS: Низкий
debian логотип

CVE-2026-38822

17 дней назад

In openNDS before 11.0.0, the client_params.sh script, invoked by the ...

CVSS3: 7.6
EPSS: Низкий
github логотип

GHSA-2h6c-w4mg-27v5

17 дней назад

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.

CVSS3: 7.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-38822

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.

CVSS3: 7.6
1%
Низкий
17 дней назад
nvd логотип
CVE-2026-38822

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.

CVSS3: 7.6
1%
Низкий
17 дней назад
debian логотип
CVE-2026-38822

In openNDS before 11.0.0, the client_params.sh script, invoked by the ...

CVSS3: 7.6
1%
Низкий
17 дней назад
github логотип
GHSA-2h6c-w4mg-27v5

In openNDS before 11.0.0, the client_params.sh script, invoked by the openNDS daemon to serve the authenticated client status page, is vulnerable to OS command injection through crafted HTTP GET query parameter keys. An authenticated captive portal user can inject arbitrary shell commands by embedding semicolons in a URL query parameter name.

CVSS3: 7.6
1%
Низкий
17 дней назад

Уязвимостей на страницу