Command Injection in ajaxdata.php in TerraMaster TOS 3.1.03: Execution of System Commands via checkName Parameter

Command Injection in ajaxdata.php in TerraMaster TOS 3.1.03: Execution of System Commands via checkName Parameter

CVE-2018-13358 · HIGH Severity

AV:N/AC:L/AU:S/C:C/I:C/A:C

System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "checkName" parameter.

Learn more about our Web Application Penetration Testing UK.