Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5vc6-rv77-8xmg

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.8

Описание

Prior to ITMS 8.1 RU4, the Symantec Management Console can be susceptible to a directory traversal exploit, which is a type of attack that can occur when there is insufficient security validation / sanitization of user-supplied input file names, such that characters representing "traverse to parent directory" are passed through to the file APIs.

Prior to ITMS 8.1 RU4, the Symantec Management Console can be susceptible to a directory traversal exploit, which is a type of attack that can occur when there is insufficient security validation / sanitization of user-supplied input file names, such that characters representing "traverse to parent directory" are passed through to the file APIs.

EPSS

Процентиль: 65%
0.00484
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.8
nvd
около 8 лет назад

Prior to ITMS 8.1 RU4, the Symantec Management Console can be susceptible to a directory traversal exploit, which is a type of attack that can occur when there is insufficient security validation / sanitization of user-supplied input file names, such that characters representing "traverse to parent directory" are passed through to the file APIs.

EPSS

Процентиль: 65%
0.00484
Низкий

6.8 Medium

CVSS3

Дефекты

CWE-22