OpenBase 10.0.5 and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to the (1) AsciiBackup, (2) OEMLicenseInstall, and possibly other stored procedures.
References
Configurations
Information
Published : 2007-11-09 18:46
Updated : 2017-07-28 18:33
NVD link : CVE-2007-5926
Mitre link : CVE-2007-5926
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
openbase_international_ltd
- openbase