Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-13779

Опубликовано: 14 сент. 2017
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-server.vbs from the "C:\GST Offline Tool" directory, which has insecure permissions. This allows local users to gain privileges by replacing winstart-server.vbs with arbitrary VBScript code. For example, a local user could create VBScript code for a TCP reverse shell, and use that later for Remote Command Execution.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gstn:india_goods_and_services_tax_network_offline_utility_tool:*:*:*:*:*:*:*:*
Версия до 1.1 (включая)

EPSS

Процентиль: 59%
0.00379
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-server.vbs from the "C:\GST Offline Tool" directory, which has insecure permissions. This allows local users to gain privileges by replacing winstart-server.vbs with arbitrary VBScript code. For example, a local user could create VBScript code for a TCP reverse shell, and use that later for Remote Command Execution.

EPSS

Процентиль: 59%
0.00379
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-732