Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-463f-727w-pqp7

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.7

Описание

nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site. This vulnerability appears to have been fixed in 7.7.

nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site. This vulnerability appears to have been fixed in 7.7.

EPSS

Процентиль: 40%
0.00183
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.7
ubuntu
почти 8 лет назад

nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site. This vulnerability appears to have been fixed in 7.7.

CVSS3: 5.5
redhat
почти 8 лет назад

nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site. This vulnerability appears to have been fixed in 7.7.

CVSS3: 5.7
nvd
почти 8 лет назад

nmap version 6.49BETA6 through 7.60, up to and including SVN revision 37147 contains a Directory Traversal vulnerability in NSE script http-fetch that can result in file overwrite as the user is running it. This attack appears to be exploitable via a victim that runs NSE script http-fetch against a malicious web site. This vulnerability appears to have been fixed in 7.7.

CVSS3: 5.7
debian
почти 8 лет назад

nmap version 6.49BETA6 through 7.60, up to and including SVN revision ...

EPSS

Процентиль: 40%
0.00183
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-22