Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2p67-36h6-33v6

Опубликовано: 23 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of the following parameters to the end of the URL: %00 %0a, %20, %2a, %a0, %aa, %c0 and %ca.

An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of the following parameters to the end of the URL: %00 %0a, %20, %2a, %a0, %aa, %c0 and %ca.

EPSS

Процентиль: 25%
0.00084
Низкий

7.5 High

CVSS3

Дефекты

CWE-538

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

An information exposure vulnerability has been found, the exploitation of which could allow a remote user to retrieve sensitive information stored on the server such as credential files, configuration files, application files, etc., simply by appending any of the following parameters to the end of the URL: %00 %0a, %20, %2a, %a0, %aa, %c0 and %ca.

EPSS

Процентиль: 25%
0.00084
Низкий

7.5 High

CVSS3

Дефекты

CWE-538