PT-2018-13954 · Nmap · Nmap4J

Zhutougg

·

Publicado

2018-09-19

·

Atualizado

2019-10-03

·

CVE-2018-17228

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions nmap4j version 1.1.0
Description The issue allows attackers to execute arbitrary commands via shell metacharacters in an includeHosts call.
Recommendations For nmap4j version 1.1.0, consider restricting the use of the includeHosts call until a patch is available to prevent the execution of arbitrary commands.

Exploit

Correção

OS Command Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-17228

Produtos afetados

Nmap4J