Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fc65-58v2-9r8h

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.

DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.

EPSS

Процентиль: 91%
0.0703
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 9.8
nvd
больше 22 лет назад

DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a connection status in the resulting error message.

EPSS

Процентиль: 91%
0.0703
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-918