pfSense pfBlockerNG up to and including 2.1.4_26 allows remote malicious users to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
netgate pfblockerng |