vendor:
sar2html
by:
Musyoka Ian
9.8
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: sar2html
Affected Version From: 3.2.1
Affected Version To: 3.2.1
Patch Exists: YES
Related CWE: N/A
CPE: a:cemtan:sar2html:3.2.1
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 18.04.1
2020
Exploit Title: sar2html 3.2.1 – ‘plot’ Remote Code Execution
A vulnerability exists in sar2html 3.2.1 which allows an attacker to execute arbitrary code on the vulnerable system. This is due to the application not properly validating user-supplied input before using it in a system call. An attacker can exploit this vulnerability by sending a specially crafted HTTP request containing malicious code to the vulnerable server. Successful exploitation of this vulnerability could result in arbitrary code execution on the vulnerable system.
Mitigation:
Upgrade to the latest version of sar2html 3.2.1 or apply the appropriate patch.