Explore Vulnerabilities SQL Injection Cross-Site Scripting (XSS) Buffer Overflow Denial of Service Remote Code Execution Remote File Include Directory Traversal HTML Injection Stack Overflow Authentication Bypass
by: Ahmet Ümit BAYRAM vendor: 7 Sticky Notes Project Show More 7 Sticky Notes v1.9 – OS Command Injection 7 Sticky Notes v1.9 allows OS command injection via the 'Alarms' feature. By setting an alarm with a malicious command in the 'Action' field, an attacker can execute arbitrary commands on the underlying operating system. 7.1 CVSS HIGH OS Command Injection 78 CWE Product Name 7 Sticky Notes Platforms Tested Windows Affected Version From: 1.9 To: 1.9 2023