Описание
The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability allows attackers to execute arbitrary commands via a crafted payload injected into the Host header.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:parallels:remote_application_server:18.0:*:*:*:*:*:*:*
EPSS
Процентиль: 67%
0.00546
Низкий
8.1 High
CVSS3
Дефекты
CWE-116
CWE-116
Связанные уязвимости
CVSS3: 8.1
github
около 3 лет назад
The Web Client of Parallels Remote Application Server v18.0 is vulnerable to Host Header Injection attacks. This vulnerability allows attackers to execute arbitrary commands via a crafted payload injected into the Host header.
EPSS
Процентиль: 67%
0.00546
Низкий
8.1 High
CVSS3
Дефекты
CWE-116
CWE-116