Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q229-jw7v-jgr4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a failed login attempt returns the command-injection output to a limited login failure field). This is fixed in 16.6.

The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a failed login attempt returns the command-injection output to a limited login failure field). This is fixed in 16.6.

EPSS

Процентиль: 95%
0.19436
Средний

Связанные уязвимости

CVSS3: 9.8
nvd
около 6 лет назад

The application login page in AKIPS Network Monitor 15.37 through 16.5 allows a remote unauthenticated attacker to execute arbitrary OS commands via shell metacharacters in the username parameter (a failed login attempt returns the command-injection output to a limited login failure field). This is fixed in 16.6.

EPSS

Процентиль: 95%
0.19436
Средний