9.3
CVE-2015-2846
- EPSS 3.65%
- Veröffentlicht 13.04.2015 14:59:03
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bittorrent ≫ Sync Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.65% | 0.882 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.3 | 8.6 | 10 |
AV:N/AC:M/Au:N/C:C/I:C/A:C
|
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')
The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.
http://www.securityfocus.com/bid/73906
http://www.zerodayinitiative.com/advisories/ZDI-15-115/