Описание
OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient input validation when constructing shell commands.
Ссылки
- Product
Уязвимые конфигурации
Конфигурация 1Версия до 1.0.3 (исключая)
Одновременно
cpe:2.3:a:rapid7:insightconnect_traceroute:*:*:*:*:*:rapid7:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
EPSS
Процентиль: 48%
0.00675
Низкий
7.7 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 7.7
github
около 1 месяца назад
OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out request parameters due to insufficient input validation when constructing shell commands.
EPSS
Процентиль: 48%
0.00675
Низкий
7.7 High
CVSS3
9.8 Critical
CVSS3
Дефекты
CWE-78