Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m65m-xrgm-j736

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.

The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.

EPSS

Процентиль: 82%
0.01763
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-178

Связанные уязвимости

CVSS3: 9.8
nvd
почти 21 год назад

The file extension check in GNUBoard 3.40 and earlier only verifies extensions that contain all lowercase letters, which allows remote attackers to upload arbitrary files via file extensions that include uppercase letters.

EPSS

Процентиль: 82%
0.01763
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-178