Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pq4v-8cpp-x9jj

Опубликовано: 09 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.

Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.

EPSS

Процентиль: 78%
0.0117
Низкий

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

Directory travesal in /northstar/filemanager/download.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to download arbitrary files, including JSP source code, across the filesystem of the host of the web application.

EPSS

Процентиль: 78%
0.0117
Низкий

Дефекты

CWE-22