TROYANOSYVIRUS
Retour aux CVEs

CVE-2024-36360

CRITICAL
9.8

Description

OS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and earlier. If a remote unauthenticated attacker sends a specially crafted HTTP request, an arbitrary OS command may be executed with the privileges of the affected product on the machine running the product.

Details CVE

Score CVSS v3.19.8
SeveriteCRITICAL
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisNONE
Interaction utilisateurNONE
Publie6/11/2024
Derniere modification3/14/2025
Sourcenvd
Observations honeypot0

Faiblesses (CWE)

CWE-78

References

https://jvn.jp/en/jp/JVN80506242/(vultures@jpcert.or.jp)
https://github.com/yammerjp/awkblog/issues/1(af854a3a-2127-422b-91ae-364da2661108)
https://jvn.jp/en/jp/JVN80506242/(af854a3a-2127-422b-91ae-364da2661108)

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.