Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9p6-c7w6-484h

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds directory.

Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds directory.

EPSS

Процентиль: 93%
0.09856
Низкий

Дефекты

CWE-22

Связанные уязвимости

ubuntu
больше 17 лет назад

Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds directory.

nvd
больше 17 лет назад

Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to read arbitrary files via a full path in the URL parameter to modules/Feeds/Feed.php, which places the contents into a related cache file in the .cache/feeds directory.

debian
больше 17 лет назад

Absolute path traversal vulnerability in SugarCRM Sugar Community Edit ...

EPSS

Процентиль: 93%
0.09856
Низкий

Дефекты

CWE-22