Home
HIGH: 7.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:L/SC:L/SI:L/SA:L/S:N/AU:N/R:U/V:D/RE:M/U:GreenDefault status
unaffected
5.0.105 (custom) before 5.0.106
affected
Description
Improper Neutralization of Special Elements in the backup name field may allow OS command injection. This issue affects Pandora ITSM 5.0.105.
Problem types
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
5.0.105 (custom) before 5.0.106
Credits
h00die-gr3y (h00die.gr3y@gmail.com)
References
pandorafms.com/...rity/common-vulnerabilities-and-exposures/