The functionality for synchronization in HGiga OAKlouds' certain moudules has an OS Command Injection vulnerability, allowing remote attackers to inject system commands within specific request parameters. This enables the execution of arbitrary code on the remote server without permission.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: twcert
Published: 2024-02-15T02:18:34.668Z
Updated: 2024-08-21T15:28:01.013Z
Reserved: 2024-02-15T01:33:48.679Z
Link: CVE-2024-26260
Vulnrichment
Updated: 2024-08-02T00:07:17.865Z
NVD
Status : Awaiting Analysis
Published: 2024-02-15T03:15:34.833
Modified: 2024-11-21T09:02:15.367
Link: CVE-2024-26260
Redhat
No data.