Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6ff5-r6p2-hm4h

Опубликовано: 03 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an unauthenticated user to perform a local file inclusion (LFI) via the /tools/webinterface/index.php?page parameter by sending a GET request. This vulnerability could lead to the loading of a PHP file on the server, leading to a critical webshell exploit.

A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an unauthenticated user to perform a local file inclusion (LFI) via the /tools/webinterface/index.php?page parameter by sending a GET request. This vulnerability could lead to the loading of a PHP file on the server, leading to a critical webshell exploit.

EPSS

Процентиль: 25%
0.00088
Низкий

7.5 High

CVSS3

Дефекты

CWE-829

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

A local file inclusion vulnerability has been found in WPN-XM Serverstack affecting version 0.8.6, which would allow an unauthenticated user to perform a local file inclusion (LFI) via the /tools/webinterface/index.php?page parameter by sending a GET request. This vulnerability could lead to the loading of a PHP file on the server, leading to a critical webshell exploit.

EPSS

Процентиль: 25%
0.00088
Низкий

7.5 High

CVSS3

Дефекты

CWE-829