CVE-2018-19646
CRITICALImperva SecureSphere <13.2.10 - Command Injection
Title source: llmDescription
The Python CGI scripts in PWS in Imperva SecureSphere 13.0.10, 13.1.10, and 13.2.10 allow remote attackers to execute arbitrary OS commands because command-line arguments are mishandled.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by rsp3ar · pythonwebappslinux
https://www.exploit-db.com/exploits/45542
Scores
CVSS v3
9.8
EPSS
0.0261
EPSS Percentile
85.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (3)
imperva/securesphere
13.0.10
imperva/securesphere
13.1.10
imperva/securesphere
13.2.10
Published
Nov 28, 2018
Tracked Since
Feb 18, 2026