Record summary

CVE-2021-32305 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.

Description

WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Aug 30, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Repository PoCs
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

Proofs of concept

2

Catalogued exploits

ExploitDBWebsvn 2.6.0 - Remote Code Execution (Unauthenticated)ExploitDB exploitby g0ldm45kNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubFredBrave/CVE-2021-32305-websvn-2.6.0Repository PoCby FredBraveStars: 1Not analyzed2 files

2.0 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALWebsvn <2.6.1 - Remote Code ExecutionCVSS 9.8

WebSVN before 2.6.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the search parameter.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.

Remediation

Upgrade Websvn to version 2.6.1 or later to mitigate this vulnerability.

WeaknessesCWE-78
Authorsgy741
Template tagscvecve2021websvnrceoastpacketstormvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:a:websvn:websvn:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3