vendor:
Graphite Web
by:
Charlie Eriksen
7.5
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Graphite Web
Affected Version From: 2000.9.5
Affected Version To: 2000.9.10
Patch Exists: YES
Related CWE: CVE-2013-5093
CPE: a:graphite_project:graphite_web
Platforms Tested: Unix
2013
Graphite Web Unsafe Pickle Handling
This module exploits a remote code execution vulnerability in the pickle handling of the rendering code in the Graphite Web project between version 0.9.5 and 0.9.10(both included).
Mitigation:
Update to version 0.9.11 or later.