CVE-2019-16701
25.09.2019, 16:15
pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.
Vendor | Product | Version |
---|---|---|
netgate | pfsense | 2.3.4 ≤ 𝑥 < 2.4.4 |
netgate | pfsense | 2.4.4 |
netgate | pfsense | 2.4.4:p1 |
netgate | pfsense | 2.4.4:p2 |
netgate | pfsense | 2.4.4:p3 |
𝑥
= Vulnerable software versions
References