Command Injection in ajaxdata.php in TerraMaster TOS 3.1.03

Command Injection in ajaxdata.php in TerraMaster TOS 3.1.03

CVE-2018-13418 · HIGH Severity

AV:N/AC:L/AU:S/C:C/I:C/A:C

System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "newname" parameter.

Learn more about our Web Application Penetration Testing UK.