Логотип exploitDog
bind:CVE-2019-25243
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2019-25243

Количество 2

Количество 2

nvd логотип

CVE-2019-25243

около 1 месяца назад

FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-8cmh-3qph-fccm

около 1 месяца назад

FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2019-25243

FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters.

CVSS3: 8.8
1%
Низкий
около 1 месяца назад
github логотип
GHSA-8cmh-3qph-fccm

FaceSentry 6.4.8 contains an authenticated remote command injection vulnerability in pingTest.php and tcpPortTest.php scripts. Attackers can exploit unsanitized input parameters to inject and execute arbitrary shell commands with root privileges by manipulating the 'strInIP' and 'strInPort' parameters.

CVSS3: 8.8
1%
Низкий
около 1 месяца назад

Уязвимостей на страницу