Lucene search

K
cveMitreCVE-2011-2649
HistoryAug 23, 2011 - 9:55 p.m.

CVE-2011-2649

2011-08-2321:55:01
CWE-20
mitre
web.nvd.nist.gov
25
cve-2011-2649
kiwi
suse studio
arbitrary command execution
shell metacharacters
nvd

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

High

EPSS

0.005

Percentile

75.6%

Kiwi before 3.74.2, as used in SUSE Studio 1.1 before 1.1.4, allows attackers to execute arbitrary commands via shell metacharacters in an unspecified FileUtils function call.

Affected configurations

Nvd
Node
marcus_schaferkiwiRange3.74.1
OR
novellsuse_studio_onsiteMatch1.1
VendorProductVersionCPE
marcus_schaferkiwi*cpe:2.3:a:marcus_schafer:kiwi:*:*:*:*:*:*:*:*
novellsuse_studio_onsite1.1cpe:2.3:a:novell:suse_studio_onsite:1.1:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

High

EPSS

0.005

Percentile

75.6%

Related for CVE-2011-2649