Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6882-w5r7-3gf2

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Directory traversal vulnerability in OpenBase 10.0.5 and earlier allows remote authenticated users to create files with arbitrary contents via a .. (dot dot) in the first argument to the GlobalLog stored procedure. NOTE: this can be leveraged to execute arbitrary code using CVE-2007-5926.

Directory traversal vulnerability in OpenBase 10.0.5 and earlier allows remote authenticated users to create files with arbitrary contents via a .. (dot dot) in the first argument to the GlobalLog stored procedure. NOTE: this can be leveraged to execute arbitrary code using CVE-2007-5926.

EPSS

Процентиль: 70%
0.00646
Низкий

8.1 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.1
nvd
около 18 лет назад

Directory traversal vulnerability in OpenBase 10.0.5 and earlier allows remote authenticated users to create files with arbitrary contents via a .. (dot dot) in the first argument to the GlobalLog stored procedure. NOTE: this can be leveraged to execute arbitrary code using CVE-2007-5926.

EPSS

Процентиль: 70%
0.00646
Низкий

8.1 High

CVSS3

Дефекты

CWE-22