The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.
References
Configurations
History
21 Nov 2024, 01:54
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
References | () http://osvdb.org/99143 - | |
References | () http://www.exploit-db.com/exploits/29323 - Exploit | |
References | () http://www.securityfocus.com/bid/62873 - | |
References | () https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-foss-disclosures-part-one - | |
References | () https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats - Exploit |
01 Aug 2024, 14:35
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : 9.0
v3 : 8.8 |
Information
Published : 2014-09-29 22:55
Updated : 2024-11-21 01:54
NVD link : CVE-2013-3632
Mitre link : CVE-2013-3632
CVE.ORG link : CVE-2013-3632
JSON object : View
Products Affected
openmediavault
- openmediavault
CWE
CWE-264
Permissions, Privileges, and Access Controls