Description
OpenBase 10.0.5 and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in arguments to the (1) AsciiBackup, (2) OEMLicenseInstall, and possibly other stored procedures.
Affected products
Exploits & proofs of concept
- exploit-dbOpenBase 10.0.x - Remote Buffer Overflow / Remote Command Executionby Kevin Finisterre
Updated 6m ago · 8 sources