Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
8.8
CVE-2023-50094
- EPSS 13.54%
- Veröffentlicht 01.01.2024 18:15:09
- Zuletzt bearbeitet 17.04.2025 19:15:57
reNgine before 2.1.2 allows OS Command Injection if an adversary has a valid session ID. The attack places shell metacharacters in an api/tools/waf_detector/?url= string. The commands are executed as root via subprocess.check_output.
9.8
CVE-2022-36566
- EPSS 2.15%
- Veröffentlicht 31.08.2022 18:15:08
- Zuletzt bearbeitet 21.11.2024 07:13:19
Rengine v1.3.0 was discovered to contain a command injection vulnerability via the scan engine function.
9.8
CVE-2022-28995
- EPSS 2.3%
- Veröffentlicht 20.05.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 06:58:18
Rengine v1.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the yaml configuration function.
9.8
CVE-2021-38606
- EPSS 1.2%
- Veröffentlicht 12.08.2021 16:15:10
- Zuletzt bearbeitet 21.11.2024 06:17:40
reNgine through 0.5 relies on a predictable directory name.