Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2021-26612

An improper input validation leading to arbitrary file creation was discovered in copy method of Nexacro platform. Remote attackers use copy method to execute arbitrary command after the file creation included malicious code.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.7%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 7.5
Products affected by CVE-2021-26612
  • Tobesoft » Nexacro » Version: 14.0.0.0
    cpe:2.3:a:tobesoft:nexacro:14.0.0.0
  • Tobesoft » Nexacro » Version: 14.0.1.3600
    cpe:2.3:a:tobesoft:nexacro:14.0.1.3600
  • Tobesoft » Nexacro » Version: 17.1.2.500
    cpe:2.3:a:tobesoft:nexacro:17.1.2.500
  • Microsoft » Windows » Version: N/A
    cpe:2.3:o:microsoft:windows:-


Contact Us

Shodan ® - All rights reserved