Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9wpj-c4wh-w9mh

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 2.7

Описание

Path Traversal in admin/assetmanager/assetmanager.php (vulnerable function saved in admin/assetmanager/functions.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to list the files that are stored on the webserver using a dot-dot-slash sequence (../) via the POST parameter inpCurrFolder.

Path Traversal in admin/assetmanager/assetmanager.php (vulnerable function saved in admin/assetmanager/functions.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to list the files that are stored on the webserver using a dot-dot-slash sequence (../) via the POST parameter inpCurrFolder.

EPSS

Процентиль: 61%
0.00418
Низкий

2.7 Low

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 2.7
nvd
почти 6 лет назад

Path Traversal in admin/assetmanager/assetmanager.php (vulnerable function saved in admin/assetmanager/functions.php) in Chadha PHPKB Standard Multi-Language 9 allows attackers to list the files that are stored on the webserver using a dot-dot-slash sequence (../) via the POST parameter inpCurrFolder.

EPSS

Процентиль: 61%
0.00418
Низкий

2.7 Low

CVSS3

Дефекты

CWE-22