#
Data Leakage
77 entries
Every Data Leakage entry VulnWatch has indexed, sorted by publication date.
Subscribe to this tag's RSS feed
High
github
Authenticated (user role) arbitrary command execution by modifying `start_cmd` setting (GHSL-2023-268)
### Summary Nginx-UI is a web interface to manage Nginx configurations. It is vulnerable to arbitrary command execution by abusing the configuration settings. ### Details The `Home > Preference` page...
7.1
CVSS
2 years ago
High
github
Authenticated (user role) remote command execution by modifying `nginx` settings (GHSL-2023-269)
### Summary The `Home > Preference` page exposes a small list of nginx settings such as `Nginx Access Log Path` and `Nginx Error Log Path`. However, the API also exposes `test_config_cmd`, `reload_cmd...
7.7
CVSS
2 years ago