viewrq.php in nweb2fax 0.2.7 and previous versions allows remote malicious users to execute arbitrary code via shell metacharacters in the var_filename parameter in a (1) tif or (2) pdf format action.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
dirk bartley nweb2fax 0.2.6 |
||
dirk bartley nweb2fax 0.2.5 |
||
dirk bartley nweb2fax 0.2.4 |
||
dirk bartley nweb2fax 0.2.1 |
||
dirk bartley nweb2fax |
||
dirk bartley nweb2fax 0.1 |
||
dirk bartley nweb2fax 0.2 |