Логотип exploitDog
bind:CVE-2023-53981
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-53981

Количество 2

Количество 2

nvd логотип

CVE-2023-53981

около 2 месяцев назад

PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftran path configuration. Attackers can exploit the ffmpeg configuration settings by base64 encoding a reverse shell command and executing it through a crafted video upload process.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-hmwx-xj5h-5xh5

около 2 месяцев назад

PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftran path configuration. Attackers can exploit the ffmpeg configuration settings by base64 encoding a reverse shell command and executing it through a crafted video upload process.

CVSS3: 8.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-53981

PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftran path configuration. Attackers can exploit the ffmpeg configuration settings by base64 encoding a reverse shell command and executing it through a crafted video upload process.

CVSS3: 7.2
1%
Низкий
около 2 месяцев назад
github логотип
GHSA-hmwx-xj5h-5xh5

PhotoShow 3.0 contains a remote code execution vulnerability that allows authenticated administrators to inject malicious commands through the exiftran path configuration. Attackers can exploit the ffmpeg configuration settings by base64 encoding a reverse shell command and executing it through a crafted video upload process.

CVSS3: 8.8
1%
Низкий
около 2 месяцев назад

Уязвимостей на страницу