Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j74m-254j-542g

Опубликовано: 26 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 10

Описание

An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are later incorporated into OS commands without adequate validation. This could allow an unauthenticated attacker to execute arbitrary commands remotely.

An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are later incorporated into OS commands without adequate validation. This could allow an unauthenticated attacker to execute arbitrary commands remotely.

EPSS

Процентиль: 93%
0.09796
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 10
nvd
2 месяца назад

An OS command injection vulnerability exists due to insufficient sanitization of user-supplied input. The application accepts parameters that are later incorporated into OS commands without adequate validation. This could allow an unauthenticated attacker to execute arbitrary commands remotely.

CVSS3: 10
fstec
2 месяца назад

Уязвимость микропрограммного обеспечения IP-видеодомофонов Zenitel TCIV-3+, связанная с непринятием мер по нейтрализации специальных элементов, используемых в команде операционной системы, позволяющая нарушителю выполнить произвольные команды

EPSS

Процентиль: 93%
0.09796
Низкий

10 Critical

CVSS4

10 Critical

CVSS3

Дефекты

CWE-78