Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2018-9246

Опубликовано: 08 июн. 2018
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5
CVSS3: 9.8

Описание

The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command execution, resulting in shell code injection via the create(), run_file(), backup(), or restore() function. The vulnerability allows unauthorized users to execute code with the same privileges as the running application.

РелизСтатусПримечание
artful

ignored

end of life
bionic

ignored

end of standard support, was needs-triage
cosmic

ignored

end of life
devel

not-affected

0.130.1-1
disco

not-affected

0.130.1-1
eoan

not-affected

0.130.1-1
esm-apps/bionic

needs-triage

esm-apps/focal

not-affected

0.130.1-1
esm-apps/jammy

not-affected

0.130.1-1
esm-apps/noble

not-affected

0.130.1-1

Показывать по

Ссылки на источники

EPSS

Процентиль: 76%
0.00971
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 7 лет назад

The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command execution, resulting in shell code injection via the create(), run_file(), backup(), or restore() function. The vulnerability allows unauthorized users to execute code with the same privileges as the running application.

CVSS3: 9.8
debian
больше 7 лет назад

The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in ...

CVSS3: 9.8
github
больше 3 лет назад

The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command execution, resulting in shell code injection via the create(), run_file(), backup(), or restore() function. The vulnerability allows unauthorized users to execute code with the same privileges as the running application.

EPSS

Процентиль: 76%
0.00971
Низкий

7.5 High

CVSS2

9.8 Critical

CVSS3