← Back to browse · API

CVE-2011-10017

Severity
CRITICAL
CVSS
10.0
EPSS
0.01915
Risk score
40.67
CISA KEV
No
PoC
No
Published
2025-08-13
Modified
2026-05-15
First seen
2026-08-07
Aliases
EUVD-2011-5241, GHSA-789Q-465M-47R2
Products
Symmetrix Technologies:Snort Report 0 <1.3.2
Sources
euvd EUVD-2011-5241

Description

Snort Report versions < 1.3.2 contains a remote command execution vulnerability in the nmap.php and nbtscan.php scripts. These scripts fail to properly sanitize user input passed via the target GET parameter, allowing attackers to inject arbitrary shell commands. Exploitation requires no authentication and can result in full compromise of the underlying system.

References