Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cv79-ff7v-6vx6

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The (1) Traceroute and (2) Ping implementations in tools.php in SpamTitan WebTitan before 3.60 allow remote authenticated users to execute arbitrary commands via shell metacharacters in an argument, as demonstrated by an && (ampersand ampersand) sequence.

The (1) Traceroute and (2) Ping implementations in tools.php in SpamTitan WebTitan before 3.60 allow remote authenticated users to execute arbitrary commands via shell metacharacters in an argument, as demonstrated by an && (ampersand ampersand) sequence.

EPSS

Процентиль: 79%
0.01272
Низкий

Дефекты

CWE-94

Связанные уязвимости

nvd
больше 13 лет назад

The (1) Traceroute and (2) Ping implementations in tools.php in SpamTitan WebTitan before 3.60 allow remote authenticated users to execute arbitrary commands via shell metacharacters in an argument, as demonstrated by an && (ampersand ampersand) sequence.

EPSS

Процентиль: 79%
0.01272
Низкий

Дефекты

CWE-94