Vulnerability Details CVE-2018-16367
In OnlineJudge 2.0, the sandbox has an incorrect access control vulnerability that can write a file anywhere. A user can write a directory listing to /tmp, and can leak file data with a #include.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 75.1%
CVSS Severity
CVSS v3 Score 9.9
CVSS v2 Score 9.0
Products affected by CVE-2018-16367
-
cpe:2.3:a:qduoj:onlinejudge:2.0