Record summary

CVE-2010-4099 has a selected CVSS score of 6.8; EIP currently links 2 catalogued exploits.

Description

ess.pm in NitroSecurity NitroView ESM 8.4.0a, when ESSPMDebug is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the Request parameter to ess.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBNitroSecurity ESM 8.4.0a - Remote Code ExecutionExploitDB exploitby Filip PalianNot analyzed1 file
ExploitDB

PoC details
ExploitDBNitroView ESM - 'ess.pm' Remote Command ExecutionExploitDB exploitby s_nNot analyzed1 file
ExploitDB

PoC details

References

5