Home / os / win10

Trixbox 2.8.0.4 Remote Code Execution

Posted on 28 May 2021

Trixbox version 2.8.0.4 has an OS command injection vulnerability that can be leveraged via shell metacharacters in the lang parameter to /maint/modules/home/index.php.

 

TOP