Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mc82-q5x6-w3v2

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ".." sequences in the archive parameter to index.php, which leaks the full pathname in an error message.

Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ".." sequences in the archive parameter to index.php, which leaks the full pathname in an error message.

EPSS

Процентиль: 51%
0.00283
Низкий

Связанные уязвимости

nvd
почти 20 лет назад

Directory traversal vulnerability in FarsiNews 2.5.3 Pro and earlier allows remote attackers to obtain the installation path via ".." sequences in the archive parameter to index.php, which leaks the full pathname in an error message.

EPSS

Процентиль: 51%
0.00283
Низкий