CMD_DB in JBMC Software DirectAdmin before 1.334 allows...
High severity
Unreviewed
Published
May 2, 2022
to the GitHub Advisory Database
•
Updated Jan 31, 2023
Description
Published by the National Vulnerability Database
May 5, 2009
Published to the GitHub Advisory Database
May 2, 2022
Last updated
Jan 31, 2023
CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action.
References