SQL Injection in logtable.php in TerraMaster TOS version 3.1.03: Exploiting the Event Parameter

SQL Injection in logtable.php in TerraMaster TOS version 3.1.03: Exploiting the Event Parameter

CVE-2018-13350 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.

Learn more about our Web Application Penetration Testing UK.