Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-12483

Опубликовано: 04 авг. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 9
CVSS3: 8.8

Описание

OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analyser rzo GET parameter is concatenated to a string used in an exec() call in the PHP code. Authentication is needed in order to exploit this vulnerability.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

not-affected

2.5+dfsg-1
disco

not-affected

2.5+dfsg-1
eoan

not-affected

2.5+dfsg-1
esm-apps/bionic

needed

esm-apps/focal

not-affected

2.5+dfsg-1
esm-apps/jammy

not-affected

2.5+dfsg-1
esm-apps/noble

not-affected

2.5+dfsg-1
esm-apps/xenial

needed

Показывать по

EPSS

Процентиль: 82%
0.01736
Низкий

9 Critical

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
больше 7 лет назад

OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analyser rzo GET parameter is concatenated to a string used in an exec() call in the PHP code. Authentication is needed in order to exploit this vulnerability.

CVSS3: 8.8
debian
больше 7 лет назад

OCS Inventory 2.4.1 is prone to a remote command-execution vulnerabili ...

CVSS3: 8.8
github
больше 3 лет назад

OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analyser rzo GET parameter is concatenated to a string used in an exec() call in the PHP code. Authentication is needed in order to exploit this vulnerability.

EPSS

Процентиль: 82%
0.01736
Низкий

9 Critical

CVSS2

8.8 High

CVSS3