Hgiga|iSherlock - OS Command Injection
50Vexday Risk Score
Prioritize patching. It exploitation observed by VulnCheck.
ssvc Actcvss 9.3epss 1.4%
from disclosure to weapon
Published on NVDJul 14
VulnCheckJul 11
exploitation probability
1.4%top 30% of all CVEs
observed exploitation
yesVulnCheck
The iSherlock developed by Hgiga has an OS Command Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary OS commands and execute them on the server. This vulnerability has already been exploited. Please update immediately.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N