Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qf2-7vj7-p7mr

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.

The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.

EPSS

Процентиль: 91%
0.06958
Низкий

Связанные уязвимости

nvd
около 23 лет назад

The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.

EPSS

Процентиль: 91%
0.06958
Низкий