Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-77v9-4x76-g7mj

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer.php in 8.x and DAV/Server.php in 7.x.

An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer.php in 8.x and DAV/Server.php in 7.x.

EPSS

Процентиль: 98%
0.507
Средний

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 9.8
nvd
почти 5 лет назад

An issue was discovered in AfterLogic Aurora through 8.5.3 and WebMail Pro through 8.5.3, when DAV is enabled. They allow directory traversal to create new files (such as an executable file under the web root). This is related to DAVServer.php in 8.x and DAV/Server.php in 7.x.

EPSS

Процентиль: 98%
0.507
Средний

Дефекты

CWE-22