Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m8j4-7vqm-v48x

Опубликовано: 14 июн. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory, allowing arbitrary system commands to be executed upon browsing the webpage.

The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory, allowing arbitrary system commands to be executed upon browsing the webpage.

EPSS

Процентиль: 77%
0.01051
Низкий

7.2 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
больше 1 года назад

The upload functionality of ASUS Download Master does not properly filter user input. Remote attackers with administrative privilege can exploit this vulnerability to upload any file to any location. They may even upload malicious web page files to the website directory, allowing arbitrary system commands to be executed upon browsing the webpage.

EPSS

Процентиль: 77%
0.01051
Низкий

7.2 High

CVSS3

Дефекты

CWE-434