Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h3rg-qv35-27xm

Опубликовано: 30 авг. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.

6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.

EPSS

Процентиль: 83%
0.01928
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
больше 1 года назад

6SHR system from Gether Technology does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload web shell scripts and use them to execute arbitrary system commands on the server.

EPSS

Процентиль: 83%
0.01928
Низкий

8.8 High

CVSS3

Дефекты

CWE-434