ZeroHour
Full Disclosurepublished ()ingested

[0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8)

mediumVulnerabilityimportance 38
AI summary · glm-5.3-flash

0day Rubbish discloses a CVSS 8.8 shell command injection in core-admin 1.0.164 via ineffective quote escaping, enabling authenticated remote code execution.

0day Rubbish Research Team publicly disclosed a systemic shell command injection (CWE-78) in core-admin 1.0.164 (build 16468). The flaw stems from ineffective quote escaping and scores 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). The disclosure does not mention a CVE identifier or observed exploitation in the wild.

  • Shell command injection via ineffective quote escaping (CWE-78) in core-admin 1.0.164 build 16468
  • CVSS 8.8 network vector requiring low privileges with no user interaction
  • Publicly disclosed as a 0day; no patch or exploitation details given
Full article

Posted by disclosure via Fulldisclosure on Sep 08 TO: fulldisclosure () seclists org SUBJECT: [0day-rubbish] core-admin 1.0.164 (build 16468) Systemic shell command injection via ineffective quote escaping (8.8) FROM: disclosure () 0day-rubbish com ----BODY---- 0day Rubbish Research Team is publicly disclosing a vulnerability in core-admin 1.0.164 (build 16468). Type: Systemic shell command injection via ineffective quote escaping (CWE-78) CVSS: 8.8 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)...

This source does not provide full text. Read it at seclists.org.