PT-2018-13587 · Oracle · Apex-Publish-Static-Files

Abdilahrf

·

Publicado

2018-10-30

·

Atualizado

2019-10-09

·

CVE-2018-16462

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions apex-publish-static-files versions prior to 2.0.1
Description A command injection issue allows arbitrary shell command execution through a maliciously crafted argument. This is exploitable if user input is passed into the connectString option in the publish method.
Recommendations Update to version 2.0.1 or later. As a temporary workaround, consider restricting user input passed into the connectString option in the publish method to minimize the risk of exploitation.

Exploit

Correção

Command Injection

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-16462
GHSA-9JM3-5835-537M

Produtos afetados

Apex-Publish-Static-Files