PT-2017-15163 · Smalruby · Smalruby+1

Shoji Baba

·

Publicado

2017-04-28

·

Atualizado

2022-05-13

·

CVE-2017-2096

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions smalruby-editor versions prior to 0.4.1 smalruby versions prior to 0.1.11
Description The issue allows remote attackers to execute arbitrary OS commands via unspecified vectors.
Recommendations For smalruby-editor versions prior to 0.4.1, update to version 0.4.1 or later. For smalruby versions prior to 0.1.11, update to version 0.1.11 or later.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-2096
GHSA-F489-655R-X6GR

Produtos afetados

Smalruby
Smalruby-Editor