Описание
Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.
Ссылки
- ExploitPatchVendor Advisory
- ExploitPatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.79 (включая)
cpe:2.3:a:bajie:java_http_server:*:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.06018
Низкий
7.5 High
CVSS2
Дефекты
CWE-94
Связанные уязвимости
github
больше 3 лет назад
Bajie HTTP JServer 0.78, and other versions before 0.80, allows remote attackers to execute arbitrary commands via shell metacharacters in an HTTP request for a CGI program that does not exist.
EPSS
Процентиль: 90%
0.06018
Низкий
7.5 High
CVSS2
Дефекты
CWE-94