Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2011-3180

Опубликовано: 16 апр. 2014
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.

Комментарий

Per: https://cwe.mitre.org/data/definitions/77.html

"CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')"

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:suse:kiwi:*:*:*:*:*:*:*:*
Версия до 4.98.07 (включая)
cpe:2.3:a:suse:studio_extension_for_system_z:1.2:*:*:*:*:*:*:*
cpe:2.3:a:suse:studio_onsite:1.2:*:*:*:*:*:*:*

EPSS

Процентиль: 81%
0.01486
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
больше 3 лет назад

kiwi before 4.98.08, as used in SUSE Studio Onsite 1.2 before 1.2.1 and SUSE Studio Extension for System z 1.2 before 1.2.1, allows attackers to execute arbitrary commands via shell metacharacters in the path of an overlay file, related to chown.

EPSS

Процентиль: 81%
0.01486
Низкий

7.5 High

CVSS2

Дефекты

NVD-CWE-Other