Description
The N-Reporter, N-Cloud, and N-Probe developed by N-Partner has an OS Command Injection vulnerability, allowing authenticated remote attackers to inject arbitrary OS commands and execute them on the server.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
6 (custom) before 6.1.187
7 (custom) before 7.0.009
6 (custom) before 6.1.187
7 (custom) before 7.0.009
6 (custom) before 6.1.187
7 (custom) before 7.0.009
References
www.twcert.org.tw/tw/cp-132-10386-231ae-1.html
www.twcert.org.tw/en/cp-139-10387-b8a4e-2.html