Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2021-3317

Disclosure Date: January 26, 2021 (last updated February 22, 2025)
KLog Server through 2.4.1 allows authenticated command injection. async.php calls shell_exec() on the original value of the source parameter.
Attacker Value
Unknown

CVE-2020-35729

Disclosure Date: December 27, 2020 (last updated February 22, 2025)
KLog Server 2.4.1 allows OS command injection via shell metacharacters in the actions/authenticate.php user parameter.