Back to search
CVE-2018-14417
Published: Aug 3, 2018
Modified: Aug 5, 2024
PUBLISHED
Description
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
104914
vdb-entry
x_refsource_BID
45097
exploit
x_refsource_EXPLOIT-DB
https://docs.softnas.com/display/SD/Release+Notes
x_refsource_CONFIRM
20180726 [CORE-2018-0009] - SoftNAS Cloud OS Command Injection
mailing-list
x_refsource_FULLDISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now