Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hm9w-m367-w8fp

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory, as demonstrated by accessing C:\folder2 when the root directory is C:\folder.

Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory, as demonstrated by accessing C:\folder2 when the root directory is C:\folder.

EPSS

Процентиль: 73%
0.00749
Низкий

Связанные уязвимости

nvd
около 19 лет назад

Winamp Web Interface (Wawi) 7.5.13 and earlier uses an insufficient comparison to determine whether a directory is located below the application's root directory, which allows remote authenticated users to access certain other directories if the name of the root directory is a substring of the name of the target directory, as demonstrated by accessing C:\folder2 when the root directory is C:\folder.

EPSS

Процентиль: 73%
0.00749
Низкий