801
VMScore

CVE-2016-10709

Published: 22/01/2018 Updated: 09/02/2018
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

pfSense prior to 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph parameter, related to _rrd_graph_img.php.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pfsense pfsense

Github Repositories

Resolucion de la maquina

Sense-HTB Resolucion de la maquina NMAP sudo nmap -sSV -p80,443 101297669 -oN scan Tenemos el puerto 80 y el 443 abieto FFUF Aunque se necesito hacer esto recursivamente y se tuvo que usar el Dirbuster ffuf -r -fc 404 -t 100 -w /usr/share/wordlists/seclists/Discovery/Web-Content/directory-list-23-mediumtxt -u 101297669/