Security Advisory

CVE-2016-10709

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-01-22 04:00:00
Last updated 2024-08-06 03:30:20
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph parameter, related to _rrd_graph_img.php.