Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q2fj-rm78-5v8m

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Unrestricted file upload vulnerability in the Manage Project functionality in Livetecs Timelive before 6.5.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in a predictable directory in Uploads/.

Unrestricted file upload vulnerability in the Manage Project functionality in Livetecs Timelive before 6.5.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in a predictable directory in Uploads/.

EPSS

Процентиль: 81%
0.01521
Низкий

Связанные уязвимости

nvd
почти 12 лет назад

Unrestricted file upload vulnerability in the Manage Project functionality in Livetecs Timelive before 6.5.1 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in a predictable directory in Uploads/.

EPSS

Процентиль: 81%
0.01521
Низкий