Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gxg9-f69x-c3pw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path traversal vulnerability in the untar method which can be exploited to write arbitrary files to arbitrary locations on the host file system when the module is run on a malicious HTTP server.

The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path traversal vulnerability in the untar method which can be exploited to write arbitrary files to arbitrary locations on the host file system when the module is run on a malicious HTTP server.

EPSS

Процентиль: 61%
0.0041
Низкий

7.5 High

CVSS3

Дефекты

CWE-22
CWE-23

Связанные уязвимости

CVSS3: 8.1
nvd
больше 5 лет назад

The Metasploit Framework module "auxiliary/admin/http/telpho10_credential_dump" module is affected by a relative path traversal vulnerability in the untar method which can be exploited to write arbitrary files to arbitrary locations on the host file system when the module is run on a malicious HTTP server.

EPSS

Процентиль: 61%
0.0041
Низкий

7.5 High

CVSS3

Дефекты

CWE-22
CWE-23