Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-828r-vvg2-xh7q

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands.

In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands.

EPSS

Процентиль: 71%
0.00689
Низкий

7.5 High

CVSS3

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

In TitanHQ SpamTitan through 7.03, a vulnerability exists in the spam rule update function. Updates are downloaded over HTTP, including scripts which are subsequently executed with root permissions. An attacker with a privileged network position is trivially able to inject arbitrary commands.

EPSS

Процентиль: 71%
0.00689
Низкий

7.5 High

CVSS3

Дефекты

CWE-74