Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cx5g-qjmj-w6xf

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.

Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.

EPSS

Процентиль: 99%
0.85112
Высокий

7.2 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.2
nvd
почти 10 лет назад

Directory traversal vulnerability in the import users feature in Micro Focus Novell Service Desk before 7.2 allows remote authenticated administrators to upload and execute arbitrary JSP files via a .. (dot dot) in a filename within a multipart/form-data POST request to a LiveTime.woa URL.

EPSS

Процентиль: 99%
0.85112
Высокий

7.2 High

CVSS3

Дефекты

CWE-22