Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jq9r-vxcv-j9c9

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

** DISPUTED ** 360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.system("PowerShell"), within a .py file. NOTE: the vendor's position is that this cannot be categorized as a vulnerability, although it is a security-related issue.

** DISPUTED ** 360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.system("PowerShell"), within a .py file. NOTE: the vendor's position is that this cannot be categorized as a vulnerability, although it is a security-related issue.

EPSS

Процентиль: 49%
0.00261
Низкий

6.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.3
nvd
больше 7 лет назад

360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or os.system("PowerShell"), within a .py file. NOTE: the vendor's position is that this cannot be categorized as a vulnerability, although it is a security-related issue

EPSS

Процентиль: 49%
0.00261
Низкий

6.3 Medium

CVSS3