Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Iansmith123

#25522of 53,632
9.8Total CVSS
Vulnerabilities · 1
PT-2019-9169
9.8
2019-06-21
Glot · Glot-Www · CVE-2018-15747
**Name of the Vulnerable Software and Affected Versions** glot-www versions through 2018-05-19 **Description** The default configuration of glot-www allows remote attackers to execute arbitrary code because glot-code-runner supports `os.system` within a "python" "files" "content" JSON file. **Recommendations** For glot-www versions through 2018-05-19, consider disabling the `os.system` function within the glot-code-runner to prevent remote code execution until a patch is available. Restrict access to the "python" "files" "content" JSON file to minimize the risk of exploitation.