pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.
2019-09-25T16:15:12.353
2024-11-21T04:31:00.590
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | netgate | pfsense | < 2.4.4 | Yes |
Application | netgate | pfsense | 2.4.4 | Yes |
Application | netgate | pfsense | 2.4.4 | Yes |
Application | netgate | pfsense | 2.4.4 | Yes |
Application | netgate | pfsense | 2.4.4 | Yes |