Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2024-8517

Опубликовано: 06 сент. 2024
Источник: ubuntu
Приоритет: medium
CVSS3: 9.8

Описание

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.

РелизСтатусПримечание
devel

not-affected

4.3.8+dfsg-1
esm-apps-legacy/xenial

needed

esm-apps/bionic

released

3.1.4-4~deb9u5ubuntu0.1~esm2
esm-apps/focal

released

3.2.7-1ubuntu0.1+esm2
esm-apps/jammy

needed

esm-apps/noble

needed

esm-apps/resolute

not-affected

4.3.8+dfsg-1
esm-apps/xenial

ignored

end of ESM support, was needed
focal

ignored

end of standard support, was needed
jammy

needed

Показывать по

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 2 лет назад

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.

CVSS3: 9.8
debian
около 2 лет назад

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command inje ...

CVSS3: 9.8
github
около 2 лет назад

SPIP before 4.3.2, 4.2.16, and 4.1.18 is vulnerable to a command injection issue. A remote and unauthenticated attacker can execute arbitrary operating system commands by sending a crafted multipart file upload HTTP request.

9.8 Critical

CVSS3