CVE-2020-24032
18.08.2020, 21:15
tz.pl on XoruX LPAR2RRD and STOR2RRD 2.70 virtual appliances allows cmd=set&tz=OS command injection via shell metacharacters in a timezone.
Vendor | Product | Version |
---|---|---|
xorux | lpar2rrd | 2.7.0 |
xorux | stor2rrd | 2.7.0 |
𝑥
= Vulnerable software versions