Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-40870

Опубликовано: 23 нояб. 2022
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability allows attackers to execute arbitrary commands via a crafted payload injected into the Host header.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:parallels:remote_application_server:18.0:*:*:*:*:*:*:*

EPSS

Процентиль: 67%
0.00546
Низкий

8.1 High

CVSS3

Дефекты

CWE-116
CWE-116

Связанные уязвимости

CVSS3: 8.1
github
около 3 лет назад

The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability allows attackers to execute arbitrary commands via a crafted payload injected into the Host header.

EPSS

Процентиль: 67%
0.00546
Низкий

8.1 High

CVSS3

Дефекты

CWE-116
CWE-116