Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7v73-wqmq-pqv5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.

PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.

EPSS

Процентиль: 88%
0.03809
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

PandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a relative path is used in the requests.

EPSS

Процентиль: 88%
0.03809
Низкий

Дефекты

CWE-434