Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jcp2-3g53-9xq3

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 6.5

Описание

url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:// substring.

url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:// substring.

EPSS

Процентиль: 51%
0.00285
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 8 лет назад

url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:// substring.

CVSS3: 6.5
nvd
больше 8 лет назад

url_check_format in include/functions.inc.php in Piwigo before 2.8.3 allows remote attackers to bypass intended access restrictions via a URL that contains a " character, or a URL beginning with a substring other than the http:// or https:// substring.

CVSS3: 6.5
debian
больше 8 лет назад

url_check_format in include/functions.inc.php in Piwigo before 2.8.3 a ...

EPSS

Процентиль: 51%
0.00285
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-284