Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6f8p-g935-8f29

Опубликовано: 27 янв. 2022
Источник: github
Github: Не прошло ревью

Описание

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

EPSS

Процентиль: 82%
0.01728
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 4 лет назад

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

CVSS3: 8.8
nvd
около 4 лет назад

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

CVSS3: 8.8
debian
около 4 лет назад

SPIP 4.0.0 is affected by a remote command execution vulnerability. To ...

EPSS

Процентиль: 82%
0.01728
Низкий

Дефекты

CWE-434