Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-76mr-hhhx-xpg8

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFile, as demonstrated by a large directory traversal sequence, which reveals the installation path in an error message.

SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFile, as demonstrated by a large directory traversal sequence, which reveals the installation path in an error message.

EPSS

Процентиль: 99%
0.80831
Высокий

Дефекты

CWE-200

Связанные уязвимости

nvd
больше 10 лет назад

SysAid Help Desk before 15.2 allows remote attackers to obtain sensitive information via an invalid value in the accountid parameter to getAgentLogFile, as demonstrated by a large directory traversal sequence, which reveals the installation path in an error message.

EPSS

Процентиль: 99%
0.80831
Высокий

Дефекты

CWE-200