Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5pv5-8647-88rx

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the attach parameter to WorkOrder.do in the file attachment for a new ticket.

Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the attach parameter to WorkOrder.do in the file attachment for a new ticket.

EPSS

Процентиль: 99%
0.77036
Высокий

Дефекты

CWE-22

Связанные уязвимости

nvd
около 11 лет назад

Directory traversal vulnerability in ManageEngine SupportCenter Plus 7.9 before 7917 allows remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the attach parameter to WorkOrder.do in the file attachment for a new ticket.

EPSS

Процентиль: 99%
0.77036
Высокий

Дефекты

CWE-22