Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pfjw-c288-q656

Опубликовано: 20 сент. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privileges and executing remote code, thereby taking over the victim’s system.

This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privileges and executing remote code, thereby taking over the victim’s system.

EPSS

Процентиль: 68%
0.00557
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8.8
nvd
больше 3 лет назад

This vulnerability of SecureGate is SQL-Injection using login without password. A path traversal vulnerability is also identified during file transfer. An attacker can take advantage of these vulnerabilities to perform various attacks such as obtaining privileges and executing remote code, thereby taking over the victim’s system.

EPSS

Процентиль: 68%
0.00557
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-22