« Volver al listado

CVE-2018-5197

Estado: ModificadaAlta (7.8)—

A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command parameters. An crafted malicious parameters could cause arbitrary command to execute.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-5197",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "vuln@krcert.or.kr",
      "affectedData": [
        {
          "vendor": "TOBESOFT",
          "product": "XPLATFORM ActiveX",
          "versions": [
            {
              "status": "affected",
              "version": "extcommon.dll 9.2, 9.2.1, 9.2.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-01-02T14:29:00.360",
  "references": [
    {
      "url": "http://support.tobesoft.co.kr/Support/index.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vuln@krcert.or.kr"
    },
    {
      "url": "https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=30097",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vuln@krcert.or.kr"
    },
    {
      "url": "http://support.tobesoft.co.kr/Support/index.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=30097",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in the ExtCommon.dll user extension module version 9.2, 9.2.1, 9.2.2 of Xplatform ActiveX could allow attacker to perform a command injection attack. The vulnerability is due to insufficient input validation of command parameters. An crafted malicious parameters could cause arbitrary command to execute."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en el módulo de extensión de usuario del tipo \"ExtCommon.dll\" en las versiones 9.2, 9.2.1 y 9.2.2 de Xplatform ActiveX podría permitir a los atacantes realizar un ataque de inyección de comandos. La vulnerabilidad se debe a la validación de entradas insuficiente de los parámetros de comandos. Los parámetros maliciosos manipulados podrían provocar la ejecución de un comando arbitrario."
    }
  ],
  "lastModified": "2026-06-17T01:59:49.563",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:tobesoft:xplatform:9.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32A3070D-31CF-4085-AD51-929E1DAE70DA"
            },
            {
              "criteria": "cpe:2.3:a:tobesoft:xplatform:9.2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B977BED8-92C8-4C9F-B5E8-5FA631CB4EA7"
            },
            {
              "criteria": "cpe:2.3:a:tobesoft:xplatform:9.2.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A6A7AFE9-8D16-4646-BB9C-182A1B5D64DD"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "vuln@krcert.or.kr"
}