Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5g7c-hgmm-663x

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

eventapp/lib/gcloud.rb in the ISUCON5 qualifier portal (aka eventapp) web application before 2015-10-30 makes improper popen calls, which allows remote attackers to execute arbitrary commands via an HTTP request that includes shell metacharacters in an argument to a "gcloud compute" command.

eventapp/lib/gcloud.rb in the ISUCON5 qualifier portal (aka eventapp) web application before 2015-10-30 makes improper popen calls, which allows remote attackers to execute arbitrary commands via an HTTP request that includes shell metacharacters in an argument to a "gcloud compute" command.

EPSS

Процентиль: 66%
0.00516
Низкий

Дефекты

CWE-78

Связанные уязвимости

nvd
больше 10 лет назад

eventapp/lib/gcloud.rb in the ISUCON5 qualifier portal (aka eventapp) web application before 2015-10-30 makes improper popen calls, which allows remote attackers to execute arbitrary commands via an HTTP request that includes shell metacharacters in an argument to a "gcloud compute" command.

EPSS

Процентиль: 66%
0.00516
Низкий

Дефекты

CWE-78