Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-7319

Опубликовано: 07 нояб. 2017
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 10
CVSS3: 9.8

Описание

The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection and arbitrary command execution if untrusted input is used.

РелизСтатусПримечание
artful

ignored

end of life
bionic

DNE

cosmic

DNE

devel

DNE

disco

DNE

eoan

DNE

esm-apps-legacy/xenial

needed

esm-apps/xenial

ignored

end of ESM support, was needed
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was needed]
esm-infra/focal

DNE

Показывать по

EPSS

Процентиль: 93%
0.06189
Низкий

10 Critical

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
почти 9 лет назад

The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection and arbitrary command execution if untrusted input is used.

CVSS3: 9.8
debian
почти 9 лет назад

The Net::Ping::External extension through 0.15 for Perl does not prope ...

CVSS3: 9.8
github
около 4 лет назад

The Net::Ping::External extension through 0.15 for Perl does not properly sanitize arguments (e.g., invalid hostnames) containing shell metacharacters before use of backticks in External.pm, allowing for shell command injection and arbitrary command execution if untrusted input is used.

CVSS3: 9.8
fstec
больше 18 лет назад

Уязвимость функции ping расширения Net::Ping::External для Perl, позволяющая нарушителю выполнять произвольные команды

EPSS

Процентиль: 93%
0.06189
Низкий

10 Critical

CVSS2

9.8 Critical

CVSS3