Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-14857

Опубликовано: 06 авг. 2018
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server through 2.5 allows a privileged user to gain access to the server via a template file containing PHP code, because file extensions other than .html are permitted.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:ocsinventory-ng:ocs_inventory_server:*:*:*:*:*:*:*:*
Версия до 2.5 (включая)

EPSS

Процентиль: 90%
0.05083
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 7 лет назад

Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server through 2.5 allows a privileged user to gain access to the server via a template file containing PHP code, because file extensions other than .html are permitted.

CVSS3: 8.8
debian
больше 7 лет назад

Unrestricted file upload (with remote code execution) in require/mail/ ...

CVSS3: 8.8
github
больше 3 лет назад

Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server through 2.5 allows a privileged user to gain access to the server via a template file containing PHP code, because file extensions other than .html are permitted.

EPSS

Процентиль: 90%
0.05083
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-434