pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_dns.php in a Create Alias action, (2) the smartmonemail value to diag_smart.php, or (3) the database value to status_rrd_graph_img.php.
References
Configurations
History
21 Nov 2024, 02:10
Type | Values Removed | Values Added |
---|---|---|
References | () https://pfsense.org/security/advisories/pfSense-SA-14_10.webgui.asc - Vendor Advisory | |
References | () https://www.exploit-db.com/exploits/43560/ - |
Information
Published : 2014-07-02 10:35
Updated : 2024-11-21 02:10
NVD link : CVE-2014-4688
Mitre link : CVE-2014-4688
CVE.ORG link : CVE-2014-4688
JSON object : View
Products Affected
netgate
- pfsense
CWE