cve/2021/CVE-2021-27886.md

18 lines
724 B
Markdown
Raw Normal View History

2024-05-25 21:48:12 +02:00
### [CVE-2021-27886](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27886)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brighgreen)
### Description
rakibtg Docker Dashboard before 2021-02-28 allows command injection in backend/utilities/terminal.js via shell metacharacters in the command parameter of an API request. NOTE: this is NOT a Docker, Inc. product.
### POC
#### Reference
- http://packetstormsecurity.com/files/163416/Docker-Dashboard-Remote-Command-Execution.html
#### Github
No PoCs found on GitHub currently.