Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2qvv-vrv2-ppx8

Опубликовано: 15 янв. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command execution.

An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command execution.

EPSS

Процентиль: 89%
0.04397
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
около 1 года назад

An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitrary code via the file upload function. The attacker can upload a malicious perlcmd.cgi file that overwrites the original upload.cgi file, enabling remote command execution.

CVSS3: 9.8
debian
около 1 года назад

An issue in GestioIP v3.5.7 allows a remote attacker to execute arbitr ...

EPSS

Процентиль: 89%
0.04397
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-434