Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2018-14857

Опубликовано: 06 авг. 2018
Источник: debian
EPSS Низкий

Описание

Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server through 2.5 allows a privileged user to gain access to the server via a template file containing PHP code, because file extensions other than .html are permitted.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ocsinventory-serverfixed2.8+dfsg1-1package

Примечания

  • Authentication is needed, only supported in trusted environments, see debtags

EPSS

Процентиль: 90%
0.05083
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server through 2.5 allows a privileged user to gain access to the server via a template file containing PHP code, because file extensions other than .html are permitted.

CVSS3: 8.8
nvd
больше 7 лет назад

Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server through 2.5 allows a privileged user to gain access to the server via a template file containing PHP code, because file extensions other than .html are permitted.

CVSS3: 8.8
github
больше 3 лет назад

Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server through 2.5 allows a privileged user to gain access to the server via a template file containing PHP code, because file extensions other than .html are permitted.

EPSS

Процентиль: 90%
0.05083
Низкий