Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ch53-6vvw-hvmw

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a direct request, and then sending an unspecified request to the download page for the backup.

mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a direct request, and then sending an unspecified request to the download page for the backup.

EPSS

Процентиль: 89%
0.04413
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 16 лет назад

mykdownload.php in MyKtools 2.4 does not require administrative authentication, which allows remote attackers to read a database backup by making a direct request, and then sending an unspecified request to the download page for the backup.

EPSS

Процентиль: 89%
0.04413
Низкий

Дефекты

CWE-287