PT-2023-7429 · Unknown · Osprey Pump Controller
CVE-2023-27886
·
Publicado
2023-03-23
·
Atualizado
2023-04-05
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Osprey Pump Controller version 1.01
Description
The issue is related to an unauthenticated OS command injection vulnerability. This vulnerability can be exploited to inject and execute arbitrary shell commands through a HTTP POST parameter. The parameter is called by the index.php script.
Recommendations
For Osprey Pump Controller version 1.01, consider disabling the HTTP POST parameter in the index.php script as a temporary workaround until a patch is available. Restrict access to the index.php script to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Osprey Pump Controller