CVE-2020-35729: Command Injection
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-35729?
The severity of CVE-2020-35729 is critical with a CVSS score of 9.8.
What is the affected software of CVE-2020-35729?
The affected software of CVE-2020-35729 is KLog Server 2.4.1.
How does CVE-2020-35729 allow OS command injection?
CVE-2020-35729 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.
Are there any known references for CVE-2020-35729?
Yes, there are known references for CVE-2020-35729. You can find them at the following links: [1](http://packetstormsecurity.com/files/160798/Klog-Server-2.4.1-Command-Injection.html), [2](http://packetstormsecurity.com/files/161123/Klog-Server-2.4.1-Command-Injection.html), [3](http://packetstormsecurity.com/files/161410/Klog-Server-2.4.1-Command-Injection.html).
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-35729?
The Common Weakness Enumeration (CWE) ID for CVE-2020-35729 is 77 and 78.