CVE-2021-47728
PoC —CVSS 4.0
9.3 critical
EPSS
3%p85
Published
()
Modified
Description
Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion techniques.
- Vendors
- selea
- Products
- izero box full firmware, izero column entry\/8 firmware, izero column full\/8 firmware, targa 504 firmware, targa 512 firmware, targa 704 ilb firmware, targa 704 tkm firmware, targa 710 inox firmware, targa 750 firmware, targa 805 firmware, targa semplice firmware, carplateserver
- Weakness
- CWE-78
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.