Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5rvx-fq47-p5r5

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.

OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.

EPSS

Процентиль: 92%
0.08931
Низкий

Связанные уязвимости

nvd
около 21 года назад

OWLS 1.0 allows remote attackers to retrieve arbitrary files via absolute pathnames in (1) the file parameter in /glossaries/index.php, (2) the filename parameter in /readings/index.php, or (3) the filename parameter in /multiplechoice/resultsignore.php, as demonstrated using /etc/passwd.

EPSS

Процентиль: 92%
0.08931
Низкий