ZeroHour

CVE-2017-16926

PoC
CVSS 3.0
9.8 critical
EPSS
6%p92
Published
()
Modified
Description

Ohcount 3.0.0 is prone to a command injection via specially crafted filenames containing shell metacharacters, which can be exploited by an attacker (providing a source tree for Ohcount processing) to execute arbitrary code as the user running Ohcount.

Vendors
ohcount project
Products
ohcount
Weakness
CWE-78
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.