Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-10665

Опубликовано: 09 сент. 2019
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

An issue was discovered in LibreNMS through 1.47. The scripts that handle the graphing options (html/includes/graphs/common.inc.php and html/includes/graphs/graphs.inc.php) do not sufficiently validate or encode several fields of user supplied input. Some parameters are filtered with mysqli_real_escape_string, which is only useful for preventing SQL injection attacks; other parameters are unfiltered. This allows an attacker to inject RRDtool syntax with newline characters via the html/graph.php script. RRDtool syntax is quite versatile and an attacker could leverage this to perform a number of attacks, including disclosing directory structure and filenames, file content, denial of service, or writing arbitrary files.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:librenms:librenms:*:*:*:*:*:*:*:*
Версия до 1.47 (включая)

EPSS

Процентиль: 0%
0.00005
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

LibreNMS Information Disclosure

EPSS

Процентиль: 0%
0.00005
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-74