← Back to CVE List

CVE-2018-14417

Published: 2018-08-04T01:29Z
Last Modified: 2024-11-21T03:49Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt