Security Advisory
CVE-2014-0121
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
The admin terminal in Hawt.io does not require authentication, which allows remote attackers to execute arbitrary commands via the k parameter.