MiczFlor RPi-Jukebox-RFID shuffle.php os command injection
38Vexday Risk Score
Sem sinal de exploração. Ela tem prova de conceito pública.
ssvc Attendcvss 5.3epss 10%
probabilidade de exploração
10%top 5% das CVEs
exploração observada
nãonenhuma fonte reporta
2 exploit(s) público(s)
A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdocs/api/playlist/shuffle.php. Executing manipulation of the argument playlist can lead to os command injection. The attack can be launched remotely. The exploit has been made available to the public and could be exploited. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Produtos afetados
MiczFlor · RPi-Jukebox-RFIDPoCs públicas encontradas — 2
cve_referencewww.exploit-db.com/exploits/52468não verificadocve_referencegithub.com/YZS17/CVE/blob/main/RPi-Jukebox-RFID/rce4.mdnão verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.