Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h76p-cpvc-jjj8

Опубликовано: 14 нояб. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow remote users to bypass SecurityManager restrictions and retrieve any file stored on the server by setting only consecutive strings ‘/...%5c’.

Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow remote users to bypass SecurityManager restrictions and retrieve any file stored on the server by setting only consecutive strings ‘/...%5c’.

EPSS

Процентиль: 26%
0.00091
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 года назад

Absolute path traversal (incorrect restriction of a path to a restricted directory) vulnerability in the EasyPHP web server, affecting version 14.1. This vulnerability could allow remote users to bypass SecurityManager restrictions and retrieve any file stored on the server by setting only consecutive strings ‘/...%5c’.

EPSS

Процентиль: 26%
0.00091
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22