Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fc6j-2mm3-rrgr

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.7

Описание

IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.

IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.

EPSS

Процентиль: 64%
0.00474
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 5.7
nvd
около 9 лет назад

IBM Kenexa LMS on Cloud could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing dot dot sequences (/../) to view arbitrary files on the system.

EPSS

Процентиль: 64%
0.00474
Низкий

5.7 Medium

CVSS3

Дефекты

CWE-22