PT-2018-13587 · Oracle · Apex-Publish-Static-Files

Abdilahrf

·

Published

2018-10-30

·

Updated

2019-10-09

·

CVE-2018-16462

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions apex-publish-static-files versions prior to 2.0.1
Description A command injection issue allows arbitrary shell command execution through a maliciously crafted argument. This is exploitable if user input is passed into the connectString option in the publish method.
Recommendations Update to version 2.0.1 or later. As a temporary workaround, consider restricting user input passed into the connectString option in the publish method to minimize the risk of exploitation.

Exploit

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-16462
GHSA-9JM3-5835-537M

Affected Products

Apex-Publish-Static-Files