Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p48v-p5pg-6rp4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable called during an installation and any arbitrary code executable using the same file name.

In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable called during an installation and any arbitrary code executable using the same file name.

EPSS

Процентиль: 24%
0.0008
Низкий

Связанные уязвимости

CVSS3: 5.8
nvd
больше 5 лет назад

In AppSpider installer versions prior to 7.2.126, the AppSpider installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from distinguishing between a valid executable called during an installation and any arbitrary code executable using the same file name.

EPSS

Процентиль: 24%
0.0008
Низкий