CVE-2018-20727
EUVD-2018-1327217.01.2019, 02:29
Multiple command injection vulnerabilities in NeDi before 1.7Cp3 allow authenticated users to execute code on the server side via the flt parameter to Nodes-Traffic.php, the dv parameter to Devices-Graph.php, or the tit parameter to drawmap.php.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nedi | nedi | 𝑥 ≤ 1.7c |
𝑥
= Vulnerable software versions