Description
ThreatSonar Anti-Ransomware developed by TeamT5 has an OS Command Injection vulnerability, allowing remote attackers with product platform intermediate privileges to inject arbitrary OS commands and execute them on the server, thereby gaining administrative access to the remote host.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
3.6.0 (custom)
References
www.twcert.org.tw/tw/cp-132-10231-a15c8-1.html
www.twcert.org.tw/en/cp-139-10232-f99c0-2.html