Логотип exploitDog
bind:CVE-2018-20218
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-20218

Количество 2

Количество 2

nvd логотип

CVE-2018-20218

почти 7 лет назад

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the "password" parameter in the login form.

CVSS3: 9.8
EPSS: Средний
github логотип

GHSA-27cv-whxj-627j

больше 3 лет назад

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the "password" parameter in the login form.

CVSS3: 9.8
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-20218

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the "password" parameter in the login form.

CVSS3: 9.8
31%
Средний
почти 7 лет назад
github логотип
GHSA-27cv-whxj-627j

An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the "password" parameter in the login form.

CVSS3: 9.8
31%
Средний
больше 3 лет назад

Уязвимостей на страницу