8.8
CVSSv3

CVE-2020-14947

Published: 30/06/2020 Updated: 28/01/2023
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

OCS Inventory NG 2.7 allows Remote Command Execution via shell metacharacters to require/commandLine/CommandLine.php because mib_file in plugins/main_sections/ms_config/ms_snmp_config.php is mishandled in get_mib_oid.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

factorfx open computer software inventory next generation 2.7

Exploits

OCS Inventory NG version 27 suffers from a remote code execution vulnerability ...

Github Repositories

The official exploit for OCS Inventory NG v2.7 Remote Command Execution CVE-2020-14947

CVE-2020-14947 The official exploit for OCS Inventory NG v27 Remote Command Execution CVE-2020-14947