An issue exists in OpenNDS prior to 10.1.3. It fails to sanitize the status path script entry in the configuration file, allowing attackers that have direct or indirect access to this file to execute arbitrary OS commands.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
opennds opennds |