CVE-2026-35847 Details
Description
An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file
A command execution vulnerability has been identified in Rainbow Aggregate DNS Management System versions through 2.15. This vulnerability allows local attackers to execute arbitrary code by exploiting the ping function in the CheckUtils.php file. The issue arises because the function fails to properly validate or sanitize the target parameter, which is directly passed to the exec() function for executing system commands. Attackers can manipulate this parameter to execute malicious commands, potentially leading to unauthorized access, data theft, or the installation of backdoors on the server.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 30, 2026CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/freedom2132/CVE/tree/main | CISA-ADP | ExploitTechnical Description |
| https://github.com/freedom2132/CVE/tree/main | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-77 | Improper Neutralization of Special Elements used in a Command ('Command Injection') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| dnsmgr | <= 2.15 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 31, 2026 | CVE Modified | CISA-ADP |
| Jul 30, 2026 | New CVE Received | [email protected] |
Volerion