peter bassill · operator
$ cve CVE-2012-0261 JSON

CVE-2012-0261 EXPLOIT

10.0
HIGH · CVSS 2.0 · EPSS 73.9% (pctl 99)

Patch early

A public exploit exists.

Description

license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the timestamp parameter for an install action.

Scoring

CVSS10.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS73.95% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-94
On CISA KEVno
Public exploityes
Published2013-12-31
Last modified2026-06-16

Affected (2)

VendorProduct
op5monitor
op5system-portal

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD