Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cq58-5c97-qv25

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.

Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.

EPSS

Процентиль: 100%
0.93355
Критический

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

Netsweeper through 6.4.3 allows unauthenticated remote code execution because webadmin/tools/unixlogin.php (with certain Referer headers) launches a command line with client-supplied parameters, and allows injection of shell metacharacters.

EPSS

Процентиль: 100%
0.93355
Критический

Дефекты

CWE-74