Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j6jw-vv8w-q769

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page immediately stops loading, which indicates whether the file exists or not.

The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page immediately stops loading, which indicates whether the file exists or not.

EPSS

Процентиль: 82%
0.01645
Низкий

Дефекты

CWE-203

Связанные уязвимости

nvd
почти 21 год назад

The NPSVG3.dll ActiveX control for Adobe SVG Viewer 3.02 and earlier, when running on Internet Explorer, allows remote attackers to determine the existence of arbitrary files by setting the src property to the target filename and using Javascript to determine if the web page immediately stops loading, which indicates whether the file exists or not.

EPSS

Процентиль: 82%
0.01645
Низкий

Дефекты

CWE-203