ABB Cylon Aspect versions 3.08.00 and below suffer from an authenticated OS command injection vulnerability. This can be exploited to inject and execute arbitrary shell commands through the timeserver HTTP POST parameter called by the setTimeServer.php script.
🛡️ VERIFIED CYBER INTELLIGENCE ID: #2344264
💾 ABB Cylon Aspect 3.08.00 setTimeServer.php Remote Code Execution
⏱️ vor 660d 23h (07.10.2024 um 15:58 Uhr) 📂 💾 IT Security Tools 📡 Feed 🔗 Quelle: packetstormsecurity.com