NONE · 0

CVE-2010-20059

FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The exec_raw.php script exposes a cmd parameter that is passed directly to the underly...

Vulnerability Description

FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The exec_raw.php script exposes a cmd parameter that is passed directly to the underlying shell without sanitation.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-20059?

CVE-2010-20059 is a documented vulnerability. FreeNAS 0.7.2 prior to revision 5543 includes an unauthenticated command‐execution backdoor in its web interface. The exec_raw.php script exposes a cmd parameter that is passed directly to the underly...

How severe is CVE-2010-20059?

CVSS scoring is not yet available for CVE-2010-20059. Check NVD for updates.

Is there a patch for CVE-2010-20059?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.