First published: Tue Nov 27 2018(Updated: )
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Terra-master Terramaster Operating System | =3.1.03 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-13358 is a vulnerability in TerraMaster TOS version 3.1.03 that allows attackers to execute system commands through a command injection in the ajaxdata.php file.
The severity of CVE-2018-13358 is critical with a CVSS score of 8.8.
Attackers can exploit CVE-2018-13358 by providing malicious input in the "checkName" parameter in ajaxdata.php, allowing them to execute system commands.
Yes, TerraMaster TOS version 3.1.03 is affected by CVE-2018-13358.
To fix CVE-2018-13358, it is recommended to update TerraMaster TOS to a version that has addressed the vulnerability.