Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5f63-p3w5-jphc

Опубликовано: 15 янв. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.

NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.

EPSS

Процентиль: 98%
0.46611
Средний

9.8 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

NUUO NVRmini2 through 3.11 allows an unauthenticated attacker to upload an encrypted TAR archive, which can be abused to add arbitrary users because of the lack of handle_import_user.php authentication. When combined with another flaw (CVE-2011-5325), it is possible to overwrite arbitrary files under the web root and achieve code execution as root.

CVSS3: 9.8
fstec
около 4 лет назад

Уязвимость сценария handle_import_user.php микропрограммного обеспечения сетевых видеорегистраторов NUUO NVRmini 2, позволяющая нарушителю получить доступ на чтение, изменение или удаление данных

EPSS

Процентиль: 98%
0.46611
Средний

9.8 Critical

CVSS3

Дефекты

CWE-306