Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6gfh-wrq3-9f83

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.6

Описание

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.

EPSS

Процентиль: 83%
0.0189
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-134

Связанные уязвимости

CVSS3: 9.6
ubuntu
около 8 лет назад

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.

CVSS3: 9.6
nvd
около 8 лет назад

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows remote attackers to conduct cross-protocol scripting attacks, and consequently execute arbitrary commands, via a crafted web site.

CVSS3: 9.6
debian
около 8 лет назад

Open On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use ...

EPSS

Процентиль: 83%
0.0189
Низкий

9.6 Critical

CVSS3

Дефекты

CWE-134