Логотип exploitDog
bind:CVE-2018-6926
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-6926

Количество 2

Количество 2

nvd логотип

CVE-2018-6926

почти 8 лет назад

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-j7gq-x7p9-9cgf

больше 3 лет назад

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2018-6926

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.

CVSS3: 7.2
1%
Низкий
почти 8 лет назад
github логотип
GHSA-j7gq-x7p9-9cgf

In app/Controller/ServersController.php in MISP 2.4.87, a server setting permitted the override of a path variable on certain Red Hed Enterprise Linux and CentOS systems (where rh_shell_fix was enabled), and consequently allowed site admins to inject arbitrary OS commands. The impact is limited by the setting being only accessible to the site administrator.

CVSS3: 7.2
1%
Низкий
больше 3 лет назад

Уязвимостей на страницу