vendor:
EasyNas
by:
Ivan Spiridonov
8.8
CVSS
HIGH
OS Command Injection
78
CWE
Product Name: EasyNas
Affected Version From: 1.1.2000
Affected Version To: 1.1.2000
Patch Exists: YES
Related CWE: CVE-2023-0830
CPE: a:easynas:easynas:1.1.0
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=49758, https://www.infosecmatter.com/nessus-plugin-library/?id=158816, https://www.infosecmatter.com/nessus-plugin-library/?id=57929, https://www.infosecmatter.com/nessus-plugin-library/?id=57928, https://www.infosecmatter.com/nessus-plugin-library/?id=57924, https://www.infosecmatter.com/nessus-plugin-library/?id=63332, https://www.infosecmatter.com/nessus-plugin-library/?id=68455, https://www.infosecmatter.com/nessus-plugin-library/?id=57105, https://www.infosecmatter.com/nessus-plugin-library/?id=134370, https://www.infosecmatter.com/nessus-plugin-library/?id=61244
Platforms Tested:
2023
EasyNas 1.1.0 – OS Command Injection
EasyNas 1.1.0 is vulnerable to OS Command Injection. An attacker can exploit this vulnerability by sending a malicious payload to the backup.pl page. The payload is then executed with root privileges, allowing the attacker to gain access to the system.
Mitigation:
Ensure that user input is properly sanitized and validated before being used in system commands.