Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pm2v-2gwc-36m2

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server.

An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server.

EPSS

Процентиль: 83%
0.01838
Низкий

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.8
nvd
около 6 лет назад

An issue was discovered in SALTO ProAccess SPACE 5.4.3.0. An attacker can write arbitrary content to arbitrary files, as demonstrated by CVE-2019-19458 files under the web root, or .bat files that will be used with auto start. This allows an attacker to execute arbitrary commands on the server.

EPSS

Процентиль: 83%
0.01838
Низкий

Дефекты

CWE-20