Description
NewSoftOA developed by NewSoft has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.
Problem types
CWE-78 Improper neutralization of special elements used in an OS command (‘OS command injection’)
Product status
Any version before 10.1.8.3
References
www.twcert.org.tw/tw/cp-132-10856-4979f-1.html
www.twcert.org.tw/en/cp-139-10857-c46f7-2.html
