Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-7178

Опубликовано: 18 мар. 2017
Источник: debian
EPSS Низкий

Описание

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
delugefixed1.3.13+git20161130.48cedf63-2package

Примечания

  • http://git.deluge-torrent.org/deluge/commit/?h=1.3-stable&id=318ab179865e0707d7945edc3a13a464a108d583

EPSS

Процентиль: 79%
0.01226
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 9 лет назад

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.

CVSS3: 8.8
nvd
почти 9 лет назад

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.

CVSS3: 8.8
github
больше 3 лет назад

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.

suse-cvrf
больше 8 лет назад

Security update for deluge

EPSS

Процентиль: 79%
0.01226
Низкий