CVE-2018-14933

upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
References
Link Resource
https://www.exploit-db.com/exploits/45070/ Exploit Third Party Advisory
https://www.exploit-db.com/exploits/46340/ Exploit Third Party Advisory
Configurations

Configuration 1


Information

Published : 2018-08-04 07:29

Updated : 2019-10-03 12:03


NVD link : CVE-2018-14933

Mitre link : CVE-2018-14933

Products Affected
No products.
CWE