Описание
Path traversal in FreeTAKServer-UI
An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbitrary files anywhere on the system.
Пакеты
Наименование
FreeTAKServer-UI
pip
Затронутые версииВерсия исправления
<= 1.9.8
Отсутствует
Связанные уязвимости
CVSS3: 6.5
nvd
почти 4 года назад
An issue in the ?filename= argument of the route /DataPackageTable in FreeTAKServer-UI v1.9.8 allows attackers to place arbitrary files anywhere on the system.