Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-95p9-wf88-ghh2

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.

By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.

EPSS

Процентиль: 75%
0.01764
Низкий

Связанные уязвимости

nvd
больше 21 года назад

By design, the built-in FTP server for iSeries AS/400 systems does not support a restricted document root, which allows attackers to read or write arbitrary files, including sensitive QSYS databases, via a full pathname in a GET or PUT request.

EPSS

Процентиль: 75%
0.01764
Низкий