Vulnerability CVE-2024-5407


Published: 2024-05-27

Description:
A vulnerability in RhinOS 3.0-1190 could allow PHP code injection through the "search" parameter in /portal/search.htm. This vulnerability could allow a remote attacker to perform a reverse shell on the remote system, compromising the entire infrastructure.

Type:

CWE-94

(Improper Control of Generation of Code ('Code Injection'))

 References:
https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-rhinos-saltos
https://github.com/josepsanzcamp/RhinOS

Copyright 2026, cxsecurity.com

 

Back to Top