9.8
CVSSv3

CVE-2018-12268

Published: 13/06/2018 Updated: 03/10/2019
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

acccheck.pl in acccheck 0.2.1 allows Command Injection via shell metacharacters in a username or password file, as demonstrated by injection into an smbclient command line.

Vulnerable Product Search on Vulmon Subscribe to Product

acccheck project acccheck.pl 0.2.1

Vendor Advisories

Debian Bug report logs - #901572 acccheck: CVE-2018-12268: Command Injection via shell metacharacters in a username or password file Package: src:acccheck; Maintainer for src:acccheck is Debian Security Tools Packaging Team <pkg-security-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg&gt ...