Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8mwh-2jgw-x22m

Опубликовано: 10 янв. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.

By abusing this vulnerability, it is possible to steal session cookies of other active users.

The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.

By abusing this vulnerability, it is possible to steal session cookies of other active users.

EPSS

Процентиль: 49%
0.00259
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 лет назад

The vulnerability allows an authenticated remote attacker to list arbitrary folders in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. By abusing this vulnerability, it is possible to steal session cookies of other active users.

CVSS3: 6.5
fstec
около 2 лет назад

Уязвимость операционной системы NEXO-OS инструментов для монтажных работ на производственных линиях Bosch Nexo cordless nutrunner и Bosch Nexo special cordless nutrunner, позволяющая нарушителю получить доступ на чтение произвольных файлов

EPSS

Процентиль: 49%
0.00259
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22