|
OSClass contains a flaw that may allow a remote attacker to execute arbitrary commands or code. The issue is due to the /oc-admin/index.php script not properly sanitizing user input supplied to the 'file' parameter. This may allow an attacker to download a file of choice from an arbitrary host, which then places the file in to an accessible location where it can be called directly.
|