| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-25616 | Cri | 0.64 | 9.9 | 0.01 | Mar 14, 2023 | In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an attacker to gain access to resources that are allowed by extra privileges. Successful attack… | ||
| CVE-2023-23857 | Cri | 0.64 | 9.9 | 0.01 | Mar 14, 2023 | Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting… | ||
| CVE-2023-27582 | Cri | 0.52 | 9.1 | 0.01 | Mar 13, 2023 | maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if SASL authorization username is specified when using the PLAIN authentication mechanisms. Instead of validating the specified… | ||
| CVE-2023-27052 | Cri | 0.64 | 9.8 | 0.01 | Mar 13, 2023 | E-Commerce System v1.0 ws discovered to contain a SQL injection vulnerability via the id parameter at /admin/delete_user.php. | ||
| CVE-2023-27583 | Cri | 0.00 | 9.8 | 0.01 | Mar 13, 2023 | PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any actions as a user with admin privileges. Version 3.1.3 has a patch for the… | ||
| CVE-2023-0354 | Cri | 0.59 | 9.1 | 0.01 | Mar 13, 2023 | The Akuvox E11 web server can be accessed without any user authentication, and this could allow an attacker to access sensitive information, as well as create and download packet captures with known default URLs. | ||
| CVE-2023-0352 | Cri | 0.59 | 9.1 | 0.01 | Mar 13, 2023 | The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the device key file. An attacker could then use this page to reset the password back to the default. | ||
| CVE-2023-0345 | Cri | 0.64 | 9.8 | 0.01 | Mar 13, 2023 | The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user. This password cannot be changed by the user. | ||
| CVE-2023-25207 | Cri | 0.64 | 9.8 | 0.01 | Mar 13, 2023 | PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php. | ||
| CVE-2023-25279 | Cri | 0.66 | 9.8 | 0.31 | Mar 13, 2023 | OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload. | ||
| CVE-2021-45423 | Cri | 0.64 | 9.8 | 0.01 | Mar 13, 2023 | A Buffer Overflow vulnerabilityexists in Pev 0.81 via the pe_exports function from exports.c.. The array offsets_to_Names is dynamically allocated on the stack using exp->NumberOfFunctions as its size. However, the loop uses exp->NumberOfNames to iterate over it and set its… | ||
| CVE-2023-0037 | Cri | 0.64 | 9.8 | 0.04 | Mar 13, 2023 | The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection | ||
| CVE-2023-27063 | Cri | 0.64 | 9.8 | 0.01 | Mar 13, 2023 | Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the DNSDomainName parameter in the formModifyDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | ||
| CVE-2023-27061 | Cri | 0.64 | 9.8 | 0.01 | Mar 13, 2023 | Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the wifiFilterListRemark parameter in the modifyWifiFilterRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request. | ||
| CVE-2023-24762 | Cri | 0.64 | 9.8 | 0.03 | Mar 13, 2023 | OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1. | ||
| CVE-2023-28154 | Cri | 0.57 | 9.8 | 0.01 | Mar 13, 2023 | Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object. | ||
| CVE-2022-48367 | Cri | 0.64 | 9.8 | 0.01 | Mar 12, 2023 | An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled. | ||
| CVE-2023-27905 | Cri | 0.63 | 9.6 | 0.02 | Mar 10, 2023 | Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting. | ||
| CVE-2023-27898 | Cri | 0.56 | 9.6 | 0.02 | Mar 10, 2023 | Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site… | ||
| CVE-2023-25143 | Cri | 0.64 | 9.8 | 0.02 | Mar 10, 2023 | An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products. | ||
| CVE-2023-1198 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities allows SQL Injection. This issue affects Starcities: through 1.3. | ||
| CVE-2022-33257 | Cri | 0.60 | 9.3 | 0.00 | Mar 10, 2023 | Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone. | ||
| CVE-2022-33256 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2023 | Memory corruption due to improper validation of array index in Multi-mode call processor. | ||
| CVE-2023-27853 | Cri | 0.65 | 9.8 | 0.20 | Mar 10, 2023 | NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device. | ||
| CVE-2023-27852 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2023 | NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the device. | ||
| CVE-2021-33360 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2023 | An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s). | ||
| CVE-2023-24774 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php. | ||
| CVE-2023-1091 | Cri | 0.64 | 9.8 | 0.01 | Mar 10, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Warehousing Automation System allows Command Line Execution through SQL Injection. This issue affects Licensed Warehousing Automation System: through 2023.1.01. | ||
| CVE-2023-1307 | Cri | 0.57 | 9.8 | 0.01 | Mar 10, 2023 | Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13. | ||
| CVE-2023-27214 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php. | ||
| CVE-2023-27213 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php. | ||
| CVE-2023-27210 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php. | ||
| CVE-2023-27207 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php. | ||
| CVE-2023-27205 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php. | ||
| CVE-2023-27204 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php. | ||
| CVE-2023-27203 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php. | ||
| CVE-2023-27202 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php. | ||
| CVE-2023-26957 | Cri | 0.59 | 9.1 | 0.01 | Mar 9, 2023 | onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins. | ||
| CVE-2023-1287 | Cri | 0.59 | 9.0 | 0.01 | Mar 9, 2023 | An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution. | ||
| CVE-2023-1251 | Cri | 0.64 | 9.8 | 0.01 | Mar 9, 2023 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akinsoft Wolvox. This issue affects Wolvox: before 8.02.03. | ||
| CVE-2023-24777 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list. | ||
| CVE-2023-1283 | Cri | 0.58 | 10.0 | 0.01 | Mar 8, 2023 | Code Injection in GitHub repository builderio/qwik prior to 0.21.0. | ||
| CVE-2021-33353 | Cri | 0.64 | 9.8 | 0.02 | Mar 8, 2023 | Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting. | ||
| CVE-2021-33352 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field. | ||
| CVE-2021-33351 | Cri | 0.59 | 9.0 | 0.01 | Mar 8, 2023 | Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field. | ||
| CVE-2023-24782 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit. | ||
| CVE-2023-22889 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users. | ||
| CVE-2023-26489 | Cri | 0.57 | 9.9 | 0.01 | Mar 8, 2023 | wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a bug on x86_64 targets where address-mode computation mistakenly would calculate a 35-bit effective address instead of WebAssembly's defined 33-bit effective… | ||
| CVE-2023-27482 | Cri | 0.71 | 10.0 | 0.72 | Mar 8, 2023 | homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1… | ||
| CVE-2023-26922 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the shell_exect parameter to the \www\pages\matrix-gui-2.0 endpoint. |
- risk 0.64cvss 9.9epss 0.01
In some scenario, SAP Business Objects Business Intelligence Platform (CMC) - versions 420, 430, Program Object execution can lead to code injection vulnerability which could allow an attacker to gain access to resources that are allowed by extra privileges. Successful attack…
- risk 0.64cvss 9.9epss 0.01
Due to missing authentication check, SAP NetWeaver AS for Java - version 7.50, allows an unauthenticated attacker to attach to an open interface and make use of an open naming and directory API to access services which can be used to perform unauthorized operations affecting…
- risk 0.52cvss 9.1epss 0.01
maddy is a composable, all-in-one mail server. Starting with version 0.2.0 and prior to version 0.6.3, maddy allows a full authentication bypass if SASL authorization username is specified when using the PLAIN authentication mechanisms. Instead of validating the specified…
- risk 0.64cvss 9.8epss 0.01
E-Commerce System v1.0 ws discovered to contain a SQL injection vulnerability via the id parameter at /admin/delete_user.php.
- risk 0.00cvss 9.8epss 0.01
PanIndex is a network disk directory index. In Panindex prior to version 3.1.3, a hard-coded JWT key `PanIndex` is used. An attacker can use the hard-coded JWT key to sign JWT token and perform any actions as a user with admin privileges. Version 3.1.3 has a patch for the…
- risk 0.59cvss 9.1epss 0.01
The Akuvox E11 web server can be accessed without any user authentication, and this could allow an attacker to access sensitive information, as well as create and download packet captures with known default URLs.
- risk 0.59cvss 9.1epss 0.01
The Akuvox E11 password recovery webpage can be accessed without authentication, and an attacker could download the device key file. An attacker could then use this page to reset the password back to the default.
- risk 0.64cvss 9.8epss 0.01
The Akuvox E11 secure shell (SSH) server is enabled by default and can be accessed by the root user. This password cannot be changed by the user.
- risk 0.64cvss 9.8epss 0.01
PrestaShop dpdfrance <6.1.3 is vulnerable to SQL Injection via dpdfrance/ajax.php.
- risk 0.66cvss 9.8epss 0.31
OS Command injection vulnerability in D-Link DIR820LA1_FW105B03 allows attackers to escalate privileges to root via a crafted payload.
- risk 0.64cvss 9.8epss 0.01
A Buffer Overflow vulnerabilityexists in Pev 0.81 via the pe_exports function from exports.c.. The array offsets_to_Names is dynamically allocated on the stack using exp->NumberOfFunctions as its size. However, the loop uses exp->NumberOfNames to iterate over it and set its…
- risk 0.64cvss 9.8epss 0.04
The 10Web Map Builder for Google Maps WordPress plugin before 1.0.73 does not properly sanitise and escape some parameters before using them in an SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection
- risk 0.64cvss 9.8epss 0.01
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the DNSDomainName parameter in the formModifyDnsForward function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
- risk 0.64cvss 9.8epss 0.01
Tenda V15V1.0 V15.11.0.14(1521_3190_1058) was discovered to contain a buffer overflow vulnerability via the wifiFilterListRemark parameter in the modifyWifiFilterRules function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted request.
- risk 0.64cvss 9.8epss 0.03
OS Command injection vulnerability in D-Link DIR-867 DIR_867_FW1.30B07 allows attackers to execute arbitrary commands via a crafted LocalIPAddress parameter for the SetVirtualServerSettings to HNAP1.
- risk 0.57cvss 9.8epss 0.01
Webpack 5 before 5.76.0 does not avoid cross-realm object access. ImportParserPlugin.js mishandles the magic comment feature. An attacker who controls a property of an untrusted object can obtain access to the real global object.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in eZ Publish Ibexa Kernel before 7.5.28. Access control based on object state is mishandled.
- risk 0.63cvss 9.6epss 0.02
Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.
- risk 0.56cvss 9.6epss 0.02
Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site…
- risk 0.64cvss 9.8epss 0.02
An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saysis Starcities allows SQL Injection. This issue affects Starcities: through 1.3.
- risk 0.60cvss 9.3epss 0.00
Memory corruption in Core due to time-of-check time-of-use race condition during dump collection in trust zone.
- risk 0.64cvss 9.8epss 0.01
Memory corruption due to improper validation of array index in Multi-mode call processor.
- risk 0.65cvss 9.8epss 0.20
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a format string vulnerability in a SOAP service that could allow an attacker to execute arbitrary code on the device.
- risk 0.64cvss 9.8epss 0.01
NETGEAR Nighthawk WiFi6 Router prior to V1.0.10.94 contains a buffer overflow vulnerability in various CGI mechanisms that could allow an attacker to execute arbitrary code on the device.
- risk 0.64cvss 9.8epss 0.01
An issue found in Stoqey gnuplot v.0.0.3 and earlier allows attackers to execute arbitrary code via the src/index.ts, plotCallack, child_process, and/or filePath parameter(s).
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the selectFields parameter at \controller\auth\Auth.php.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Warehousing Automation System allows Command Line Execution through SQL Injection. This issue affects Licensed Warehousing Automation System: through 2023.1.01.
- risk 0.57cvss 9.8epss 0.01
Authentication Bypass by Primary Weakness in GitHub repository froxlor/froxlor prior to 2.0.13.
- risk 0.64cvss 9.8epss 0.01
Online Student Management System v1.0 was discovered to contain multiple SQL injection vulnerabilities via the fromdate and todate parameters at /eduauth/student/between-date-reprtsdetails.php.
- risk 0.64cvss 9.8epss 0.01
Online Student Management System v1.0 was discovered to contain a SQL injection vulnerability via the searchdata parameter at /eduauth/student/search.php.
- risk 0.64cvss 9.8epss 0.01
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/view_order.php.
- risk 0.64cvss 9.8epss 0.01
Online Pizza Ordering System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /admin/manage_user.php.
- risk 0.64cvss 9.8epss 0.01
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the month parameter at /kruxton/sales_report.php.
- risk 0.64cvss 9.8epss 0.01
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/manage_user.php.
- risk 0.64cvss 9.8epss 0.01
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /billing/home.php.
- risk 0.64cvss 9.8epss 0.01
Best POS Management System 1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /kruxton/receipt.php.
- risk 0.59cvss 9.1epss 0.01
onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins.
- risk 0.59cvss 9.0epss 0.01
An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.
- risk 0.64cvss 9.8epss 0.01
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Akinsoft Wolvox. This issue affects Wolvox: before 8.02.03.
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/table/list.
- risk 0.58cvss 10.0epss 0.01
Code Injection in GitHub repository builderio/qwik prior to 0.21.0.
- risk 0.64cvss 9.8epss 0.02
Directory Traversal vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via the file attachment directory setting.
- risk 0.64cvss 9.8epss 0.01
An issue in Wyomind Help Desk Magento 2 extension v.1.3.6 and before fixed in v.1.3.7 allows attacker to execute arbitrary code via a phar file upload in the ticket message field.
- risk 0.59cvss 9.0epss 0.01
Cross Site Scripting Vulnerability in Wyomind Help Desk Magento 2 extension v.1.3.6 and before and fixed in v.1.3.7 allows attackers to escalte privileges via a crafted payload in the ticket message field.
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a SQL injection vulnerability via the id parameter at /databases/database/edit.
- risk 0.64cvss 9.8epss 0.01
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.
- risk 0.57cvss 9.9epss 0.01
wasmtime is a fast and secure runtime for WebAssembly. In affected versions wasmtime's code generator, Cranelift, has a bug on x86_64 targets where address-mode computation mistakenly would calculate a 35-bit effective address instead of WebAssembly's defined 33-bit effective…
- risk 0.71cvss 10.0epss 0.72
homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1…
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability found in Varisicte matrix-gui v.2 allows a remote attacker to execute arbitrary code via the shell_exect parameter to the \www\pages\matrix-gui-2.0 endpoint.