Sploitus

CVE-2016-10709

3 known exploits for CVE-2016-10709

pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph parameter, related to _rrd_graph_img.php.

Affected products
Pfsense
Pfsense
≤ 2.2.6
Fix
Available
CVSS 2.0
9.0 HIGH
CVSS 3.1
8.8 HIGH
EPSS
33.7% (98th percentile)
Weakness
CWE-78
NVD status
Modified
Published
2018-01-22
CVE-2016-10709 at NVD
Authoritative description, scoring and affected products

3 known exploits for CVE-2016-10709

Proof-of-concept code and exploit modules indexed by Sploitus