Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f937-vggr-93fv

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the pkg parameter in a do_install action to dtc/.

Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the pkg parameter in a do_install action to dtc/.

EPSS

Процентиль: 78%
0.01135
Низкий

Дефекты

CWE-22

Связанные уязвимости

ubuntu
почти 12 лет назад

Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the pkg parameter in a do_install action to dtc/.

nvd
почти 12 лет назад

Directory traversal vulnerability in shared/package-installer in Domain Technologie Control (DTC) before 0.34.1 allows remote authenticated users to execute arbitrary PHP code via a .. (dot dot) in the pkg parameter in a do_install action to dtc/.

debian
почти 12 лет назад

Directory traversal vulnerability in shared/package-installer in Domai ...

EPSS

Процентиль: 78%
0.01135
Низкий

Дефекты

CWE-22