#VU72390 OS Command Injection in C-DATA Web Management System - CVE-2022-4257
Published: February 20, 2023
C-DATA Web Management System
C-Data Technology Co.,Ltd.
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to improper input validation in "cgi-bin/jumpto.php" script when processing data passed via the "hostname" HTTP POST parameter. A remote unauthenticated attacker can send a specially crafted HTTP POST request to the application and execute arbitrary OS commands on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.