Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-492m-hh57-3gv9

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, execute arbitrary PHP code, or read arbitrary files via the GLOBALS[prefix] parameter, a different vector than CVE-2003-1500.

_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, execute arbitrary PHP code, or read arbitrary files via the GLOBALS[prefix] parameter, a different vector than CVE-2003-1500.

EPSS

Процентиль: 92%
0.08071
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-22

Связанные уязвимости

CVSS3: 9.8
nvd
больше 16 лет назад

_functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, execute arbitrary PHP code, or read arbitrary files via the GLOBALS[prefix] parameter, a different vector than CVE-2003-1500.

EPSS

Процентиль: 92%
0.08071
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-20
CWE-22