PT-2025-33086 · Snort+1 · Snort+1
Published
2025-08-13
·
Updated
2025-08-14
·
CVE-2011-10017
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions:
Snort versions prior to 1.3.2
Description:
Snort Report versions prior to 1.3.2 contain a remote command execution issue in the
nmap.php and nbtscan.php scripts. These scripts do not properly sanitize user input received through the target GET parameter, allowing attackers to inject arbitrary shell commands. Exploitation does not require authentication and can lead to a full system compromise.Recommendations:
Update Snort Report to version 1.3.2 or later.
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snort
Snort Report