Описание
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.
Ссылки
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 2.5.5 (включая)
cpe:2.3:a:quickbox:quickbox:*:*:*:*:community:*:*:*
Конфигурация 2Версия до 2.1.8 (включая)
cpe:2.3:a:quickbox:quickbox:*:*:*:*:pro:*:*:*
EPSS
Процентиль: 97%
0.40223
Средний
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-78
Связанные уязвимости
github
больше 3 лет назад
QuickBox Community Edition through 2.5.5 and Pro Edition through 2.1.8 allows an authenticated remote attacker to execute code on the server via command injection in the servicestart parameter.
EPSS
Процентиль: 97%
0.40223
Средний
8.8 High
CVSS3
9 Critical
CVSS2
Дефекты
CWE-78