Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-15865

Опубликовано: 18 авг. 2020
Источник: nvd
CVSS3: 9.8
CVSS2: 10
EPSS Низкий

Описание

A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the report XML file so that they will be compiled and executed on the server that processes this file. This can be used to fully compromise the server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:stimulsoft:reports:2013.1.1600.0:*:*:*:*:*:*:*

EPSS

Процентиль: 91%
0.06779
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
больше 3 лет назад

A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the report XML file so that they will be compiled and executed on the server that processes this file. This can be used to fully compromise the server.

EPSS

Процентиль: 91%
0.06779
Низкий

9.8 Critical

CVSS3

10 Critical

CVSS2

Дефекты

CWE-94