Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mc39-mcp7-82wg

Опубликовано: 28 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 8.4

Описание

PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system files by manipulating the 'chemin' parameter. Attackers can exploit the unsanitized file path input to access sensitive files like /etc/passwd by sending crafted requests to the getgif.php endpoint.

PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system files by manipulating the 'chemin' parameter. Attackers can exploit the unsanitized file path input to access sensitive files like /etc/passwd by sending crafted requests to the getgif.php endpoint.

EPSS

Процентиль: 4%
0.0002
Низкий

6.9 Medium

CVSS4

8.4 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.4
nvd
11 дней назад

PMB 5.6 contains a local file disclosure vulnerability in getgif.php that allows attackers to read arbitrary system files by manipulating the 'chemin' parameter. Attackers can exploit the unsanitized file path input to access sensitive files like /etc/passwd by sending crafted requests to the getgif.php endpoint.

EPSS

Процентиль: 4%
0.0002
Низкий

6.9 Medium

CVSS4

8.4 High

CVSS3

Дефекты

CWE-22