Required CVE Record Information
Description
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled.
References 2 Total
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 2 Total
- exploit-db.com: 43659 exploitx_transferred
- https://blogs.securiteam.com/index.php/archives/3548 x_transferred