Unauthenticated Remote Command injection as root occurs in the Western Digital MyCloud NAS 2.11.142 index.php page via a modified Cookie header.
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
Link | Tags |
---|---|
https://www.stevencampbell.info/2016/12/command-injection-in-western-digital-mycloud-nas/ | third party advisory exploit |
http://www.securityfocus.com/bid/95201 | vdb entry |