Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m65m-xrgm-j736

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.

The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.

EPSS

Процентиль: 84%
0.02639
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-178

Связанные уязвимости

CVSS3: 9.8
nvd
больше 21 года назад

The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.

EPSS

Процентиль: 84%
0.02639
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-178