CVE-2018-7664: OS Command Injection
An issue was discovered in ClipBucket before 4.0.0 Release 4902. Any OS commands can be injected via shell metacharacters in the filename parameter to /api/fileuploader.php or /actions/filedownloader.php.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
ClipBucketto a version that resolves this vulnerability.Fixed in 4.0.0 Release 4902
Event History
Frequently Asked Questions
What is the severity of CVE-2018-7664?
The CVE-2018-7664 vulnerability has a high severity due to the potential for arbitrary OS command injection.
How do I fix CVE-2018-7664?
To fix CVE-2018-7664, update ClipBucket to version 4.0.0 Release 4903 or higher.
What are the affected versions of ClipBucket in CVE-2018-7664?
All versions of ClipBucket before 4.0.0 Release 4902 are affected by CVE-2018-7664.
Which parameters are exploited in CVE-2018-7664?
CVE-2018-7664 is exploited through the file_name parameter in /api/file_uploader.php and /actions/file_downloader.php.
Can CVE-2018-7664 lead to data breaches?
Yes, CVE-2018-7664 can lead to unauthorized access and potential data breaches due to arbitrary command execution.