Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c52w-858f-r8xv

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated attacker to read internal files on the server via an http:IP:PORT/../../path/file_to_disclose Directory Traversal URI.

Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated attacker to read internal files on the server via an http:IP:PORT/../../path/file_to_disclose Directory Traversal URI.

EPSS

Процентиль: 94%
0.15194
Средний

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
больше 5 лет назад

Setelsa Conacwin v3.7.1.2 is vulnerable to a local file inclusion vulnerability. This vulnerability allows a remote unauthenticated attacker to read internal files on the server via an http:IP:PORT/../../path/file_to_disclose Directory Traversal URI. NOTE: The manufacturer indicated that the affected version does not exist. Furthermore, they indicated that they detected this problem in an internal audit more than 3 years ago and fixed it in 2017.

EPSS

Процентиль: 94%
0.15194
Средний

Дефекты

CWE-22