PT-2021-15460 · Unknown · Portkiller

Omnitaint

·

Published

2021-03-18

·

Updated

2022-07-12

·

CVE-2021-23359

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions port-killer versions all
Description The issue allows an attacker to execute arbitrary commands if attacker-controlled user input is given. This is due to the use of the child process exec function without input sanitization. For example, running a proof of concept will cause the command touch success to be executed, leading to the creation of a file called success.
Recommendations For all versions, consider disabling the use of the child process exec function until a patch is available. Restrict access to user input to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23359
GHSA-2548-Q746-X5X6

Affected Products

Portkiller