Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-chj6-x555-wh22

Опубликовано: 11 апр. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.

A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.

EPSS

Процентиль: 51%
0.00276
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-24

Связанные уязвимости

CVSS3: 5.3
ubuntu
10 месяцев назад

A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.

CVSS3: 5.3
nvd
10 месяцев назад

A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.

CVSS3: 5.3
debian
10 месяцев назад

A path traversal vulnerability in FusionDirectory before 1.5 allows re ...

EPSS

Процентиль: 51%
0.00276
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-24