Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-24r9-8wx9-6g9f

Опубликовано: 27 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.

EPSS

Процентиль: 98%
0.64373
Средний

9.8 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 года назад

BC Security Empire before 5.9.3 is vulnerable to a path traversal issue that can lead to remote code execution. A remote, unauthenticated attacker can exploit this vulnerability over HTTP by acting as a normal agent, completing all cryptographic handshakes, and then triggering an upload of payload data containing a malicious path.

EPSS

Процентиль: 98%
0.64373
Средний

9.8 Critical

CVSS3

Дефекты

CWE-22