In VembuBDR before 4.2.0.1 and... CVE-2021-26471

7.5 AV AC AU C I A
发布: 2021-06-08
修订: 2024-11-21

In VembuBDR before 4.2.0.1 and VembuOffsiteDR before 4.2.0.1, the http API located at /sgwebservice_o.php accepts a command argument. Using this command argument an unauthenticated attacker can execute arbitrary shell commands.

0%
暂无可用Exp或PoC
当前有2条受影响产品信息