packetstormsecurity.com
http://packetstormsecurity.com/files/171649/Sleuthkit-4.11.1-Command-Injection.html CVE-2022-45639
HIGH
sleuthkit 4.11.1 - Command Injection
Record summary
CVE-2022-45639 has a selected CVSS score of 7.8 (high); EIP currently links 1 catalogued exploit.
Description
OS Command injection vulnerability in sleuthkit fls tool 4.11.1 allows attackers to execute arbitrary commands via a crafted value to the m parameter. NOTE: third parties have disputed this because there is no analysis showing that the backtick command executes outside the context of the user account that entered the command line.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2025 · Source: CVE List
Proofs of concept
1Catalogued exploits
ExploitDBsleuthkit 4.11.1 - Command InjectionExploitDB exploitby Dino BarlattaniNot analyzed1 file
References
4binaryworld.it
http://www.binaryworld.it/ nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-45639 binaryworld.it
https://www.binaryworld.it/guidepoc.asp