Логотип exploitDog
bind:CVE-2023-38316
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-38316

Количество 4

Количество 4

ubuntu логотип

CVE-2023-38316

около 2 лет назад

An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2023-38316

около 2 лет назад

An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2023-38316

около 2 лет назад

An issue was discovered in OpenNDS Captive Portal before version 10.1. ...

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-857f-w8mj-5g2g

около 2 лет назад

An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests.

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2023-38316

An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
nvd логотип
CVE-2023-38316

An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests. Affected OpenNDS Captive Portal before version 10.1.2 fixed in OpenWrt master, OpenWrt 23.05 and OpenWrt 22.03 on 28. August 2023 by updating OpenNDS to version 10.1.3.

CVSS3: 9.8
1%
Низкий
около 2 лет назад
debian логотип
CVE-2023-38316

An issue was discovered in OpenNDS Captive Portal before version 10.1. ...

CVSS3: 9.8
1%
Низкий
около 2 лет назад
github логотип
GHSA-857f-w8mj-5g2g

An issue was discovered in OpenNDS Captive Portal before version 10.1.2. When the custom unescape callback is enabled, attackers can execute arbitrary OS commands by inserting them into the URL portion of HTTP GET requests.

CVSS3: 9.8
1%
Низкий
около 2 лет назад

Уязвимостей на страницу