Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cq82-f654-8cvc

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.

In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.

EPSS

Процентиль: 92%
0.08119
Низкий

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

In Ortus TestBox 2.4.0 through 4.1.0, unvalidated query string parameters passed to system/runners/HTMLRunner.cfm allow an attacker to write an arbitrary CFM file (within the application's context) containing attacker-defined CFML tags, leading to Remote Code Execution.

EPSS

Процентиль: 92%
0.08119
Низкий

Дефекты

CWE-77