| |
Vulnerability CVE-2018-14772
Published: 2018-10-16 Modified: 2018-10-17
Description: |
Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code on the underlying system via Command Injection. |
Type:
CWE-77 (Improper Neutralization of Special Elements used in a Command ('Command Injection'))
CVSS2 => (AV:N/AC:L/Au:S/C:C/I:C/A:C)
CVSS Base Score |
Impact Subscore |
Exploitability Subscore |
9/10 |
10/10 |
8/10 |
Exploit range |
Attack complexity |
Authentication |
Remote |
Low |
Single time |
Confidentiality impact |
Integrity impact |
Availability impact |
Complete |
Complete |
Complete |
References: |
http://coastalsec.io/cve-2018-14772-remote-code-execution
|
|
|
Copyright 2024, cxsecurity.com
|
|
|