Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9fj5-j2jg-7pxw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request.

With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request.

EPSS

Процентиль: 39%
0.00177
Низкий

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 6.7
nvd
больше 4 лет назад

With an admin account, the .htaccess file in Artica Pandora FMS <=755 can be overwritten with the File Manager component. The new .htaccess file contains a Rewrite Rule with a type definition. A normal PHP file can be uploaded with this new "file type" and the code can be executed with an HTTP request.

EPSS

Процентиль: 39%
0.00177
Низкий

Дефекты

CWE-74