← volver
CVE-2019-5029criticalCWE-78

CVE-2019-5029

60Vexday Risk Score

Haz seguimiento. Ella tiene prueba de concepto pública.

ssvc Attendcvss 9.8epss 57%
de la publicación al arma237 días
Publicada en NVD13 nov
1ª PoC+237d
probabilidad de explotación
57%top 1% de las CVE
explotación observada
noninguna fuente lo reporta
3 exploit(s) público(s)
An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() can be inserted into the editor and will be executed by the Exhibitor process when it launches ZooKeeper. An attacker can execute any command as the user running the Exhibitor process.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Productos afectados
n/a · Exhibitor
⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.