Security Advisory

CVE-2018-7664

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2018-03-05 07:00:00
Last updated 2024-08-05 06:31:05
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacters in the file_name parameter to /api/file_uploader.php or /actions/file_downloader.php.