Описание
CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action.
Ссылки
- ExploitBroken Link
- Broken Link
- Vendor Advisory
- Vendor AdvisoryRelease Notes
- Third Party Advisory
- ExploitBroken Link
- Broken Link
- Vendor Advisory
- Vendor AdvisoryRelease Notes
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.33.4 (исключая)
cpe:2.3:a:directadmin:directadmin:*:*:*:*:*:*:*:*
EPSS
Процентиль: 77%
0.01006
Низкий
8.5 High
CVSS2
Дефекты
CWE-20
Связанные уязвимости
github
почти 4 года назад
CMD_DB in JBMC Software DirectAdmin before 1.334 allows remote authenticated users to gain privileges via shell metacharacters in the name parameter during a restore action.
EPSS
Процентиль: 77%
0.01006
Низкий
8.5 High
CVSS2
Дефекты
CWE-20