Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h79m-47pc-f28h

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attacks and overwrite arbitrary files via a "....//" (dot dot) in the s parameter, which is collapsed into a "../" value.

code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attacks and overwrite arbitrary files via a "....//" (dot dot) in the s parameter, which is collapsed into a "../" value.

EPSS

Процентиль: 82%
0.01803
Низкий

Дефекты

CWE-22

Связанные уязвимости

nvd
больше 16 лет назад

code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to conduct directory traversal attacks and overwrite arbitrary files via a "....//" (dot dot) in the s parameter, which is collapsed into a "../" value.

EPSS

Процентиль: 82%
0.01803
Низкий

Дефекты

CWE-22