Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3qq7-wxv7-66wq

Опубликовано: 04 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

EPSS

Процентиль: 74%
0.00805
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 лет назад

Online Notice Board System v1.0 is vulnerable to an Insecure File Upload vulnerability on the 'f' parameter of user/update_profile_pic.php page, allowing an authenticated attacker to obtain Remote Code Execution on the server hosting the application.

EPSS

Процентиль: 74%
0.00805
Низкий

8.8 High

CVSS3

Дефекты

CWE-434