HTTP RULE(RULE ID:324079)

Rule General Information
Release Date: 2020-01-19
Rule Name: TerraMaster TOS Remote Code Execution Vulnerability (CVE-2017-9328)
Severity: Critical
CVE ID: CVE-2017-9328
Rule Protection Details
Description: Shell metacharacter injection vulnerability in /usr/www/include/ajax/GetTest.php in TerraMaster TOS before 3.0.34 leads to remote code execution as root.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Others
Reference: https://gist.github.com/hybriz/63bbe2d963e531357aca353c74dd1ad5
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
http://www.terra-master.com/html/en/