Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pc58-jh86-xjm9

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 2.7

Описание

Path Traversal in admin/imagepaster/image-renaming.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to rename any file on the webserver using a dot-dot-slash sequence (../) via the POST parameter imgName (for the new name) and imgUrl (for the current file to be renamed).

Path Traversal in admin/imagepaster/image-renaming.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to rename any file on the webserver using a dot-dot-slash sequence (../) via the POST parameter imgName (for the new name) and imgUrl (for the current file to be renamed).

EPSS

Процентиль: 60%
0.00405
Низкий

2.7 Low

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 2.7
nvd
почти 6 лет назад

Path Traversal in admin/imagepaster/image-renaming.php in Chadha PHPKB Standard Multi-Language 9 allows attackers to rename any file on the webserver using a dot-dot-slash sequence (../) via the POST parameter imgName (for the new name) and imgUrl (for the current file to be renamed).

EPSS

Процентиль: 60%
0.00405
Низкий

2.7 Low

CVSS3

Дефекты

CWE-22