Vulnerabilities > Numarasoftware > Footprints > 8.0a

DATE CVE VULNERABILITY TITLE RISK
2009-09-02 CVE-2008-7158 OS Command Injection vulnerability in Numarasoftware Footprints
Numara FootPrints 7.5a through 7.5a1 and 8.0 through 8.0a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) transcriptFile parameter to MRcgi/MRchat.pl or (2) LOADFILE parameter to MRcgi/MRABLoad2.pl.
network
low complexity
numarasoftware CWE-78
critical
10.0