Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6vh4-w25v-6gh9

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.

Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.

EPSS

Процентиль: 76%
0.00961
Низкий

Связанные уязвимости

nvd
почти 26 лет назад

Default configuration in Matt Wright FormHandler.cgi script allows arbitrary directories to be used for attachments, and only restricts access to the /etc/ directory, which allows remote attackers to read arbitrary files via the reply_message_attach attachment parameter.

EPSS

Процентиль: 76%
0.00961
Низкий