Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p5xr-f67h-9rw9

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00), which might also require (2) an authentication bypass step that involves a username with a trailing "@" characters.

The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00), which might also require (2) an authentication bypass step that involves a username with a trailing "@" characters.

EPSS

Процентиль: 78%
0.01156
Низкий

Связанные уязвимости

nvd
около 20 лет назад

The TCLHTTPd service in Lyris ListManager before 8.9b allows remote attackers to obtain source code for arbitrary .tml (TCL) files via (1) a request with a trailing null byte (%00), which might also require (2) an authentication bypass step that involves a username with a trailing "@" characters.

EPSS

Процентиль: 78%
0.01156
Низкий