PT-2025-33086 · Snort+1 · Snort+1

Published

2025-08-13

·

Updated

2025-08-14

·

CVE-2011-10017

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions: Snort versions prior to 1.3.2
Description: Snort Report versions prior to 1.3.2 contain a remote command execution issue in the nmap.php and nbtscan.php scripts. These scripts do not properly sanitize user input received through the target GET parameter, allowing attackers to inject arbitrary shell commands. Exploitation does not require authentication and can lead to a full system compromise.
Recommendations: Update Snort Report to version 1.3.2 or later.

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2011-10017

Affected Products

Snort
Snort Report