Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-12483

Опубликовано: 04 авг. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 9
CVSS3: 8.8

Описание

OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analyser rzo GET parameter is concatenated to a string used in an exec() call in the PHP code. Authentication is needed in order to exploit this vulnerability.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
cosmic

ignored

end of life
devel

DNE

disco

not-affected

2.5+dfsg-1
eoan

not-affected

2.5+dfsg-1
esm-apps-legacy/xenial

needed

esm-apps/bionic

needed

esm-apps/focal

not-affected

2.5+dfsg-1
esm-apps/jammy

not-affected

2.5+dfsg-1
esm-apps/noble

not-affected

2.5+dfsg-1

Показывать по

EPSS

Процентиль: 84%
0.02479
Низкий

9 Critical

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 8 лет назад

OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analyser rzo GET parameter is concatenated to a string used in an exec() call in the PHP code. Authentication is needed in order to exploit this vulnerability.

CVSS3: 8.8
debian
около 8 лет назад

OCS Inventory 2.4.1 is prone to a remote command-execution vulnerabili ...

CVSS3: 8.8
github
больше 4 лет назад

OCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the ipdiscover_analyser rzo GET parameter is concatenated to a string used in an exec() call in the PHP code. Authentication is needed in order to exploit this vulnerability.

EPSS

Процентиль: 84%
0.02479
Низкий

9 Critical

CVSS2

8.8 High

CVSS3