Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8j53-mpr3-63rc

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack.

Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack.

EPSS

Процентиль: 69%
0.00628
Низкий

Связанные уязвимости

nvd
почти 25 лет назад

Auction Weaver 1.0 through 1.04 does not properly validate the names of form fields, which allows remote attackers to delete arbitrary files and directories via a .. (dot dot) attack.

EPSS

Процентиль: 69%
0.00628
Низкий