VulnerabilityModified
CVE-2017-16666
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name of an uploaded PCAP file.
HIGH 8.8EPSS 80.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 80.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Xplico before 1.2.1 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the name of an uploaded PCAP file. NOTE: this issue can be exploited without authentication by leveraging the user registration feature.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 80.76% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- xplico/xplico
- Source
- cve@mitre.org
References
- http://blog.securityonion.net/2017/11/security-advisory-for-xplico-120.htmlThird Party Advisory
- http://packetstormsecurity.com/files/145639/Xplico-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.rapid7.com/db/modules/exploit/linux/http/xplico_execExploit, Third Party Advisory
- https://pentest.blog/advisory-xplico-unauthenticated-remote-code-execution-cve-2017-16666/Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/43430/Exploit, Third Party Advisory, VDB Entry
- https://www.xplico.org/archives/1538Vendor Advisory
- http://blog.securityonion.net/2017/11/security-advisory-for-xplico-120.htmlThird Party Advisory
- http://packetstormsecurity.com/files/145639/Xplico-Remote-Code-Execution.htmlExploit, Third Party Advisory, VDB Entry
- http://www.rapid7.com/db/modules/exploit/linux/http/xplico_execExploit, Third Party Advisory
- https://pentest.blog/advisory-xplico-unauthenticated-remote-code-execution-cve-2017-16666/Exploit, Third Party Advisory
- https://www.exploit-db.com/exploits/43430/Exploit, Third Party Advisory, VDB Entry
- https://www.xplico.org/archives/1538Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.