Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2021-44123

Опубликовано: 26 янв. 2022
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 6.5
CVSS3: 8.8

Описание

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

РелизСтатусПримечание
bionic

released

3.1.4-4~deb9u5build0.18.04.1
devel

not-affected

4.0.1
esm-apps/bionic

released

3.1.4-4~deb9u5build0.18.04.1
esm-apps/focal

released

3.2.7-1ubuntu0.1
esm-apps/jammy

not-affected

4.0.1
esm-apps/noble

not-affected

4.0.1
esm-apps/xenial

needed

focal

released

3.2.7-1ubuntu0.1
impish

released

3.2.11-3+deb11u3build0.21.10.1
jammy

not-affected

4.0.1

Показывать по

EPSS

Процентиль: 82%
0.01728
Низкий

6.5 Medium

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 4 лет назад

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

CVSS3: 8.8
debian
около 4 лет назад

SPIP 4.0.0 is affected by a remote command execution vulnerability. To ...

github
около 4 лет назад

SPIP 4.0.0 is affected by a remote command execution vulnerability. To exploit the vulnerability, an attacker must craft a malicious picture with a double extension, upload it and then click on it to execute it.

EPSS

Процентиль: 82%
0.01728
Низкий

6.5 Medium

CVSS2

8.8 High

CVSS3