Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

ubuntu логотип

CVE-2013-7285

около 7 лет назад

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

CVSS3: 9.8
EPSS: Высокий
redhat логотип

CVE-2013-7285

больше 12 лет назад

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

CVSS2: 6.8
EPSS: Высокий
nvd логотип

CVE-2013-7285

около 7 лет назад

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

CVSS3: 9.8
EPSS: Высокий
debian логотип

CVE-2013-7285

около 7 лет назад

Xstream API versions up to 1.4.6 and version 1.4.10, if the security f ...

CVSS3: 9.8
EPSS: Высокий
github логотип

GHSA-f554-x222-wgf7

около 7 лет назад

Command Injection in Xstream

CVSS3: 9.8
EPSS: Высокий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2013-7285

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

CVSS3: 9.8
84%
Высокий
около 7 лет назад
redhat логотип
CVE-2013-7285

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

CVSS2: 6.8
84%
Высокий
больше 12 лет назад
nvd логотип
CVE-2013-7285

Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input stream when unmarshaling XML or any supported format. e.g. JSON.

CVSS3: 9.8
84%
Высокий
около 7 лет назад
debian логотип
CVE-2013-7285

Xstream API versions up to 1.4.6 and version 1.4.10, if the security f ...

CVSS3: 9.8
84%
Высокий
около 7 лет назад
github логотип
GHSA-f554-x222-wgf7

Command Injection in Xstream

CVSS3: 9.8
84%
Высокий
около 7 лет назад

Уязвимостей на страницу