Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4pq3-767m-6x5g

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.

Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.

EPSS

Процентиль: 54%
0.00315
Низкий

Дефекты

CWE-22

Связанные уязвимости

nvd
около 21 года назад

Directory traversal vulnerability in RealOne Player, RealOne Player 2.0, and RealOne Enterprise Desktop allows remote attackers to upload arbitrary files via an RMP file that contains .. (dot dot) sequences in a .rjs skin file.

EPSS

Процентиль: 54%
0.00315
Низкий

Дефекты

CWE-22