Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-56hv-7v48-w28m

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.4

Описание

The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.

The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.

EPSS

Процентиль: 68%
0.00556
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 10 лет назад

The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.

CVSS3: 7.4
nvd
около 10 лет назад

The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL.

CVSS3: 7.4
debian
около 10 лет назад

The HTTPS fallback implementation in Shell In A Box (aka shellinabox) ...

suse-cvrf
около 9 лет назад

Security update for shellinabox

EPSS

Процентиль: 68%
0.00556
Низкий

7.4 High

CVSS3