Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9426-vxhj-rxm5

Опубликовано: 29 фев. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the Apache Axis service running on the localhost interface, leading to command execution.

An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the Apache Axis service running on the localhost interface, leading to command execution.

EPSS

Процентиль: 87%
0.03333
Низкий

8.8 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.8
nvd
почти 2 года назад

An issue was discovered in RWS WorldServer before 11.7.3. An authenticated, remote attacker can perform a ws-legacy/load_dtd?system_id= blind SSRF attack to deploy JSP code to the Apache Axis service running on the localhost interface, leading to command execution.

EPSS

Процентиль: 87%
0.03333
Низкий

8.8 High

CVSS3

Дефекты

CWE-918