CVE-2024-34852

F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transceiver_schedule.php file. An unauthenticated remote attacker can exploit this vulnerability by sending a file name containing command injection. Successful exploitation of this vulnerability may allow the attacker to execute system commands.
Configurations

No configuration.

History

No history.

Information

Published : 2024-05-28 17:15

Updated : 2024-07-03 02:00


NVD link : CVE-2024-34852

Mitre link : CVE-2024-34852

CVE.ORG link : CVE-2024-34852


JSON object : View

Products Affected

No product.

CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')