CVE-2012-0261
high · 10license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the timestamp parameter for an install action.
10
CVSS
73.9%
EPSS (exploit prob.)
99th
EPSS percentile
2013-12-31
Published
AV:N/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
CWE-94
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| op5 | monitor | <= 5.5.1 |
| op5 | monitor | 5.3.5 |
| op5 | monitor | 5.4.0 |
| op5 | monitor | 5.4.2 |
| op5 | monitor | 5.5.0 |
| op5 | system-portal | <= 1.6.1 |
Check a specific version with /api/v1/cve/match.
References
- http://seclists.org/fulldisclosure/2012/Jan/62
- http://secunia.com/advisories/47417
- http://www.ekelow.se/file_uploads/Advisories/ekelow-aid-2012-01.pdf
- http://www.op5.com/news/support-news/fixed-vulnerabilities-op5-monitor-op5-appliance/
- http://www.osvdb.org/78064
- https://bugs.op5.com/view.php?id=5094
- http://seclists.org/fulldisclosure/2012/Jan/62
- http://secunia.com/advisories/47417
- http://www.ekelow.se/file_uploads/Advisories/ekelow-aid-2012-01.pdf
- http://www.op5.com/news/support-news/fixed-vulnerabilities-op5-monitor-op5-appliance/
- http://www.osvdb.org/78064
- https://bugs.op5.com/view.php?id=5094
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2012-0261