Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mjjf-pxhg-89qq

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

EPSS

Процентиль: 78%
0.01161
Низкий

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.8
nvd
почти 5 лет назад

NeDi 1.9C allows an authenticated user to execute operating system commands in the Nodes Traffic function on the endpoint /Nodes-Traffic.php via the md or ag HTTP GET parameter. This allows an attacker to obtain access to the operating system where NeDi is installed and to all application data.

EPSS

Процентиль: 78%
0.01161
Низкий

Дефекты

CWE-78