All CVEs — page 40 of 242
The complete archive, 25 per page, newest first. 6034 records. Search instead.
The flaw allows command injection through the manipulation of the split_file_path argument in the merge_split_file function of aaPanel BaoTa up to 11.8.0, enabling remote code execution.
The flaw allows for os command injection via the url argument in the network_tools function, enabling remote attackers to execute arbitrary commands.