The web service for ONS-S8 - Spectra Aggregation Switch includes functions which do not properly validate user input, allowing an attacker to traverse directories, bypass authentication, and execute remote code.
References
Configurations
No configuration.
History
04 Oct 2024, 13:50
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
03 Oct 2024, 23:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-10-03 23:15
Updated : 2024-10-04 13:50
NVD link : CVE-2024-41925
Mitre link : CVE-2024-41925
CVE.ORG link : CVE-2024-41925
JSON object : View
Products Affected
No product.
CWE
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')