Описание
Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.
Ссылки
- Product
- PatchVendor Advisory
- ExploitPatchTechnical DescriptionThird Party Advisory
- Product
- PatchVendor Advisory
- ExploitPatchTechnical DescriptionThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.0.0 (исключая)
cpe:2.3:a:druva:insync_client:*:*:*:*:*:macos:*:*
EPSS
Процентиль: 77%
0.01071
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 7.8
github
больше 3 лет назад
Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library.
EPSS
Процентиль: 77%
0.01071
Низкий
7.8 High
CVSS3
4.6 Medium
CVSS2
Дефекты
CWE-78