7.5
CVSSv2

CVE-2018-9246

Published: 08/06/2018 Updated: 01/08/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

The PGObject::Util::DBAdmin module prior to 0.120.0 for Perl, as used in LedgerSMB up to and including 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command execution, resulting in shell code injection via the create(), run_file(), backup(), or restore() function. The vulnerability allows unauthorized users to execute code with the same privileges as the running application.

Vulnerable Product Search on Vulmon Subscribe to Product

pgobject-util-dbadmin project pgobject-util-dbadmin

ledgersmb ledgersmb

Vendor Advisories

Debian Bug report logs - #900942 CVE-2018-9246 Package: src:libpgobject-util-dbadmin-perl; Maintainer for src:libpgobject-util-dbadmin-perl is Debian Perl Group <pkg-perl-maintainers@listsaliothdebianorg>; Reported by: "Robert J Clay" <rjclay@gmailcom> Date: Thu, 7 Jun 2018 03:15:01 UTC Severity: grave Tags: fi ...