Description

OS command injection vulnerability exists in awkblog v0.0.1 (commit hash:7b761b192d0e0dc3eef0f30630e00ece01c8d552) and earlier. If a remote unauthenticated attacker sends a specially crafted HTTP request, an arbitrary OS command may be executed with the privileges of the affected product on the machine running the product.

INFO

Published Date :

2024-06-11T04:19:39.122Z

Last Modified :

2025-03-14T14:43:00.422Z

Source :

jpcert
AFFECTED PRODUCTS

The following products are affected by CVE-2024-36360 vulnerability.

Vendors Products
Keisuke Nakayama
  • Awkblog
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-36360.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact