Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-6926

Опубликовано: 12 фев. 2018
Источник: nvd
CVSS3: 7.2
CVSS2: 9
EPSS Низкий

Описание

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:misp:misp:2.4.87:*:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.00533
Низкий

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.2
github
больше 3 лет назад

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.

EPSS

Процентиль: 67%
0.00533
Низкий

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-78