QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2020-06-01T15:19:42

Updated: 2020-06-02T15:06:14

Reserved: 2020-05-25T00:00:00


Link: CVE-2020-13448

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-06-01T16:15:14.323

Modified: 2021-12-13T20:04:11.290


Link: CVE-2020-13448

JSON object: View

cve-icon Redhat Information

No data.

CWE