A command injection vulnerability in maintenance.cgi in Mutiny "Monitoring Appliance" before 6.1.0-5263 allows authenticated users, with access to the admin interface, to inject arbitrary commands within the filename of a system upgrade upload.
References
Configurations
Information
Published : 2018-08-28 10:29
Updated : 2019-10-02 17:03
NVD link : CVE-2018-15529
Mitre link : CVE-2018-15529
JSON object : View
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Products Affected
mutiny
- mutiny