Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Iansmith123

#25923de 53,635
9.8CVSS total
Vulnerabilidades · 1
PT-2019-9169
9.8
2019-06-21
Glot · Glot-Www · CVE-2018-15747
**Name of the Vulnerable Software and Affected Versions** glot-www versions through 2018-05-19 **Description** The default configuration of glot-www allows remote attackers to execute arbitrary code because glot-code-runner supports `os.system` within a "python" "files" "content" JSON file. **Recommendations** For glot-www versions through 2018-05-19, consider disabling the `os.system` function within the glot-code-runner to prevent remote code execution until a patch is available. Restrict access to the "python" "files" "content" JSON file to minimize the risk of exploitation.