PT-2018-11211 · Ocs · Ocs Inventory Ng

Juan Manuel Fernandez

·

Publicado

2018-08-03

·

Atualizado

2018-10-02

·

CVE-2018-12483

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions OCS Inventory version 2.4.1
Description The issue is a remote command-execution problem. It happens because the content of the ipdiscover analyser rzo GET parameter is concatenated to a string used in an exec() call in the PHP code. To exploit this, authentication is required.
Recommendations For OCS Inventory version 2.4.1, consider restricting access to the ipdiscover analyser module to minimize the risk of exploitation. Avoid using the rzo parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-12483

Produtos afetados

Ocs Inventory Ng