Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-7178

Опубликовано: 18 мар. 2017
Источник: nvd
CVSS3: 8.8
CVSS2: 6.8
EPSS Низкий

Описание

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its init.py file and (2) causing the victim to download, install, and enable this plugin.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:deluge-torrent:deluge:*:*:*:*:*:*:*:*
Версия до 1.3.14 (исключая)
Конфигурация 2
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

EPSS

Процентиль: 79%
0.01226
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 9 лет назад

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.

CVSS3: 8.8
debian
почти 9 лет назад

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploit ...

CVSS3: 8.8
github
больше 3 лет назад

CSRF was discovered in the web UI in Deluge before 1.3.14. The exploitation methodology involves (1) hosting a crafted plugin that executes an arbitrary program from its __init__.py file and (2) causing the victim to download, install, and enable this plugin.

suse-cvrf
больше 8 лет назад

Security update for deluge

EPSS

Процентиль: 79%
0.01226
Низкий

8.8 High

CVSS3

6.8 Medium

CVSS2

Дефекты

CWE-352