← voltar
CVE-2016-15057criticalexploração observadaCWE-77

Apache Continuum: Command injection leading to RCE

65Vexday Risk Score

Corrija agora. Ela exploração observada pelo VulnCheck e tem exploit funcional público.

ssvc Actcvss 9.9epss 3.8%
da publicação à arma0 dias
Publicada no NVD26 de jan.
metasploit6 de abr.
VulnCheck26 de jan.
probabilidade de exploração
3.8%top 11% das CVEs
exploração observada
simVulnCheck
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Continuum. This issue affects Apache Continuum: all versions. Attackers with access to the installations REST API can use this to invoke arbitrary commands on the server. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H