Files
CVEs-PoC/2013/CVE-2013-3631.md
2024-06-18 02:51:15 +02:00

915 B

CVE-2013-3631

Description

NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execute Command" feature. NOTE: this issue might not be a vulnerability, since it appears to be part of legitimate, intentionally-exposed functionality by the developer and is allowed within the intended security policy.

POC

Reference

Github

No PoCs found on GitHub currently.