Loading
Generated remediation guidance and an executive summary. No account required.
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "pwd" parameter during user creation.
Use CWE-78, Terra-Master vendor hub and Terramaster Operating System product page to widen CVE-2018-13336 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-24990, CVE-2022-24989 and CVE-2020-35665 for nearby disclosures in the same product family.