Security Advisory

CVE-2018-13336

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-11-27 21:00:00
Last updated 2024-08-05 09:00:35
Assigner mitre
State PUBLISHED

Description

System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during user creation.