board.cgi in Sepal SPBOARD 4.5 allows remote attackers to execute arbitrary commands via shell metacharacters in the file parameter during a down_file action.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Spboard | Sepal | 4.5 (including) | 4.5 (including) |