PrestaShop CVE-2013-6358 vulnerability

Core

Score

9 Critical

Date publish

23-01-2020

Versiones afectadas

  • Versions from 1.5.5.0 up to and including 1.5.5.0

Description

PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.

References

https://web.archive.org/web/201504230419...
Exploit Third Party Advisory mitre.org
https://web.archive.org/web/201504230419...
Exploit Third Party Advisory

Metrics

cvssMetricV31
sourcenvd@nist.gov
typePrimary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
baseScore8.8
baseSeverityHIGH
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredLOW
userInteractionNONE
scopeUNCHANGED
confidentialityImpactHIGH
integrityImpactHIGH
availabilityImpactHIGH
exploitabilityScore2.8
impactScore5.9
cvssMetricV2
sourcenvd@nist.gov
typePrimary
version2.0
vectorStringAV:N/AC:L/Au:S/C:C/I:C/A:C
baseScore9
accessVectorNETWORK
accessComplexityLOW
authenticationSINGLE
confidentialityImpactCOMPLETE
integrityImpactCOMPLETE
availabilityImpactCOMPLETE
baseSeverityHIGH
exploitabilityScore8
impactScore10
acInsufInfoFalse
obtainAllPrivilegeFalse
obtainUserPrivilegeFalse
obtainOtherPrivilegeFalse
userInteractionRequiredFalse
Scroll al inicio