Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vr3w-v4c5-868f

Опубликовано: 10 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via shell metacharacters within the Network Tools section of the web-management interface. All three networking tools are affected (Ping, Traceroute, and DNS Lookup) and their respective input fields (ping_address, trace_address, nslookup_address).

An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via shell metacharacters within the Network Tools section of the web-management interface. All three networking tools are affected (Ping, Traceroute, and DNS Lookup) and their respective input fields (ping_address, trace_address, nslookup_address).

EPSS

Процентиль: 94%
0.13416
Средний

8.8 High

CVSS3

Дефекты

CWE-77
CWE-78

Связанные уязвимости

CVSS3: 7.2
nvd
больше 3 лет назад

An issue was discovered in Galleon NTS-6002-GPS 4.14.103-Galleon-NTS-6002.V12 4. An authenticated attacker can perform command injection as root via shell metacharacters within the Network Tools section of the web-management interface. All three networking tools are affected (Ping, Traceroute, and DNS Lookup) and their respective input fields (ping_address, trace_address, nslookup_address).

EPSS

Процентиль: 94%
0.13416
Средний

8.8 High

CVSS3

Дефекты

CWE-77
CWE-78