Beveiligingsadvies

CVE-2020-10808

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2020-03-22 16:07:34
Laatst bijgewerkt 2024-08-04 11:14:15
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

Vesta Control Panel (VestaCP) through 0.9.8-26 allows Command Injection via the schedule/backup Backup Listing Endpoint. The attacker must be able to create a crafted filename on the server, as demonstrated by an FTP session that renames .bash_logout to a .bash_logout' substring followed by shell metacharacters.