6

CVE-2010-2236

Exploit

The monitoring probe display in spacewalk-java before 2.1.148-1 and Red Hat Network (RHN) Satellite 4.0.0 through 4.2.0 and 5.1.0 through 5.3.0, and Proxy 5.3.0, allows remote authenticated users with permissions to administer monitoring probes to execute arbitrary code via unspecified vectors, related to backticks.

Data is provided by the National Vulnerability Database (NVD)
RedhatNetwork Proxy Version5.3
RedhatSatellite Version4.0
RedhatSatellite Version4.1
RedhatSatellite Version4.2
RedhatSatellite Version5.1
RedhatSatellite Version5.2
RedhatSatellite Version5.3
RedhatSpacewalk-java Version <= 2.1.147-1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.06% 0.822
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6 6.8 6.4
AV:N/AC:M/Au:S/C:P/I:P/A:P
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.