9

CVE-2011-0018

Exploit

The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to execute arbitrary commands via the (1) To or (2) From e-mail address in an OMP request to the Greenbone Security Assistant (GSA).

Data is provided by the National Vulnerability Database (NVD)
OpenvasOpenvas Manager Version1.0.0
OpenvasOpenvas Manager Version1.0.0 Updatebeta1
OpenvasOpenvas Manager Version1.0.0 Updatebeta2
OpenvasOpenvas Manager Version1.0.0 Updatebeta3
OpenvasOpenvas Manager Version1.0.0 Updatebeta4
OpenvasOpenvas Manager Version1.0.0 Updatebeta5
OpenvasOpenvas Manager Version1.0.0 Updatebeta6
OpenvasOpenvas Manager Version1.0.0 Updatebeta7
OpenvasOpenvas Manager Version1.0.0 Updaterc1
OpenvasOpenvas Manager Version1.0.1
OpenvasOpenvas Manager Version1.0.2
OpenvasOpenvas Manager Version1.0.3
OpenvasOpenvas Manager Version2.0 Updatebeta1
OpenvasOpenvas Manager Version2.0 Updatebeta2
OpenvasOpenvas Manager Version2.0 Updatebeta3
OpenvasOpenvas Manager Version2.0 Updaterc1
OpenvasOpenvas Manager Version2.0 Updaterc2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 9.73% 0.926
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.