VDB
CVE-2011-0018
CVE-2011-0018
PUBLISHED
CVSS 9 CRITICAL
The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authenticated users to execute arbitrary commands via the (1) To or (2) From e-mail address in an OMP request to the Greenbone Security Assistant (GSA).
EPSS 11.69% · 93.8th percentile
Risk Scores
CVSS 2.0
9
EPSS Score
11.69%
93.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| openvas | openvas_manager | 2.0, 1.0.0, 1.0.0 |
| n/a | n/a | * |
Timeline
- Jan 28, 2011 CVE Published
- Jan 31, 2011 PoC Published
- Feb 1, 2011 PoC Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- 20110125 [OVSA20110118] OpenVAS Manager Vulnerable To Command Injection mailing-list
- 43037 third-party-advisory
- 45987 vdb
- http://www.openvas.org/OVSA20110118.html url
- ADV-2011-0208 vdb
- 70639 vdb
- 16086 exploit
- openvas-email-command-execution(65011) vdb
- https://nvd.nist.gov/vuln/detail/CVE-2011-0018 advisory