Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5rj7-m957-87g6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=InstallGadget&comp=FileBrowser and admin.php?reqGadget=FileBrowser&reqAction=Files to upload a .php file. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.

Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=InstallGadget&comp=FileBrowser and admin.php?reqGadget=FileBrowser&reqAction=Files to upload a .php file. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.

EPSS

Процентиль: 85%
0.02628
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
около 5 лет назад

Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of admin.php?reqGadget=Components&reqAction=InstallGadget&comp=FileBrowser and admin.php?reqGadget=FileBrowser&reqAction=Files to upload a .php file. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.

EPSS

Процентиль: 85%
0.02628
Низкий

Дефекты

CWE-434