peter bassill · operator
$ cve CVE-2010-4099 JSON

CVE-2010-4099 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 2.6% (pctl 85)

Patch early

A public exploit exists.

Description

ess.pm in NitroSecurity NitroView ESM 8.4.0a, when ESSPMDebug is enabled, allows remote attackers to execute arbitrary commands via shell metacharacters in the Request parameter to ess.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS2.63% — more likely to be exploited than 85% of all CVEs
WeaknessCWE-20
On CISA KEVno
Public exploityes
Published2010-10-27
Last modified2026-06-16

Affected (2)

VendorProduct
nitrosecuritynitroview esm
nitrosecuritynitroview esm software

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD