Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-44123

Опубликовано: 26 янв. 2022
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:spip:spip:4.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 82%
0.01728
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
ubuntu
около 4 лет назад

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

CVSS3: 8.8
debian
около 4 лет назад

SPIP 4.0.0 is affected by a remote command execution vulnerability. To ...

github
около 4 лет назад

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

EPSS

Процентиль: 82%
0.01728
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-434