Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-2195

Опубликовано: 26 окт. 2021
Источник: ubuntu
Приоритет: high
EPSS Низкий
CVSS2: 9.3
CVSS3: 9.8

Описание

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.

РелизСтатусПримечание
devel

not-affected

2.3.3-1
hardy

ignored

end of life
lucid

ignored

end of life
maverick

ignored

end of life
natty

ignored

end of life
oneiric

not-affected

precise

not-affected

2.3.3-1
quantal

not-affected

2.3.3-1
raring

not-affected

2.3.3-1
saucy

not-affected

2.3.3-1

Показывать по

EPSS

Процентиль: 87%
0.03419
Низкий

9.3 Critical

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.

CVSS3: 9.8
debian
около 4 лет назад

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the ...

github
больше 3 лет назад

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.

EPSS

Процентиль: 87%
0.03419
Низкий

9.3 Critical

CVSS2

9.8 Critical

CVSS3