Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9m79-c3rf-x6vw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the report XML file so that they will be compiled and executed on the server that processes this file. This can be used to fully compromise the server.

A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the report XML file so that they will be compiled and executed on the server that processes this file. This can be used to fully compromise the server.

EPSS

Процентиль: 91%
0.06779
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the report XML file so that they will be compiled and executed on the server that processes this file. This can be used to fully compromise the server.

EPSS

Процентиль: 91%
0.06779
Низкий

Дефекты

CWE-20