CVE-2012-0262
82Vexday Risk Score
Patch now. It exploitation observed by VulnCheck and has a working public exploit.
ssvc Actepss 73%
from disclosure to weapon370 days
Published on NVDDec 31
1st PoC+370d
metasploitJan 5
VulnCheck+2527d
exploitation probability
73%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/41687unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
https://bugs.op5.com/view.php?id=5094http://seclists.org/fulldisclosure/2012/Jan/62http://secunia.com/advisories/47417http://www.ekelow.se/file_uploads/Advisories/ekelow-aid-2012-01.pdfhttp://www.op5.com/news/support-news/fixed-vulnerabilities-op5-monitor-op5-appliance/http://www.osvdb.org/78065