Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fmmx-7c8x-cqv9

Опубликовано: 09 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.

Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.

EPSS

Процентиль: 76%
0.00958
Низкий

8.8 High

CVSS3

Дефекты

CWE-22
CWE-35

Связанные уязвимости

CVSS3: 9.8
nvd
больше 1 года назад

Directory Travel in PHPVibe v11.0.46 due to incomplete blacklist checksums and directory checks, which can lead to code execution via writing specific statements to .htaccess and code to a file with a .png suffix.

EPSS

Процентиль: 76%
0.00958
Низкий

8.8 High

CVSS3

Дефекты

CWE-22
CWE-35