Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w8w9-prcc-w4vw

Опубликовано: 02 окт. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10

Описание

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful.

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful.

EPSS

Процентиль: 71%
0.01358
Низкий

10 Critical

CVSS4

Дефекты

CWE-78

Связанные уязвимости

nvd
около 1 года назад

ContentKeeper Web Appliance (now maintained by Impero Software) versions prior to 125.10 are vulnerable to remote command execution due to insecure handling of file uploads via the mimencode CGI utility. The vulnerability allows unauthenticated attackers to upload and execute arbitrary scripts as the Apache user. Additionally, the exploit can optionally escalate privileges by abusing insecure PATH usage in the benetool binary, resulting in root-level access if successful.

EPSS

Процентиль: 71%
0.01358
Низкий

10 Critical

CVSS4

Дефекты

CWE-78