Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-2195

Опубликовано: 26 окт. 2021
Источник: nvd
CVSS3: 9.8
CVSS2: 9.3
EPSS Низкий

Описание

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:websvn:websvn:2.3.2:*:*:*:*:*:*:*

EPSS

Процентиль: 87%
0.03419
Низкий

9.8 Critical

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-78
CWE-78

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 4 лет назад

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.

CVSS3: 9.8
debian
около 4 лет назад

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the ...

github
больше 3 лет назад

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.

EPSS

Процентиль: 87%
0.03419
Низкий

9.8 Critical

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-78
CWE-78