CVE-2024-34852
May 28, 2024, 5:15 p.m.
Tags
Product(s) Impacted
F-logic DataCube3
- 1.0
Description
F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transceiver_schedule.php file. An unauthenticated remote attacker can exploit this vulnerability by sending a file name containing command injection. Successful exploitation of this vulnerability may allow the attacker to execute system commands.
Weaknesses
Date
Published: May 28, 2024, 5:15 p.m.
Last Modified: May 28, 2024, 5:15 p.m.
Status : Received
CVE has been recently published to the CVE List and has been received by the NVD.
More infoSource
cve@mitre.org
References
https://github.com/
cve@mitre.org