PT-2021-15475 · Unknown · Portkiller

Omnitaint

·

Published

2021-04-18

·

Updated

2021-05-06

·

CVE-2021-23379

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions portkiller versions all
Description The issue allows an attacker to execute arbitrary commands if attacker-controlled user input is provided. This is caused by the use of the child process exec function without proper input sanitization.
Recommendations For all versions, consider disabling the use of the child process exec function until a proper fix is implemented, and ensure all user input is sanitized to prevent arbitrary command execution.

Exploit

Fix

Command Injection

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23379
GHSA-R6FW-8M27-43C9

Affected Products

Portkiller