Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q3rm-gwvh-vhv3

Опубликовано: 22 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.

EPSS

Процентиль: 87%
0.03419
Низкий

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 4 лет назад

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.

CVSS3: 9.8
nvd
около 4 лет назад

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the 'allowDownload' option is enabled in config.php, an attacker can invoke the dl.php script and pass a well formed 'path' argument to execute arbitrary commands against the underlying operating system.

CVSS3: 9.8
debian
около 4 лет назад

A flaw was found in WebSVN 2.3.2. Without prior authentication, if the ...

EPSS

Процентиль: 87%
0.03419
Низкий

Дефекты

CWE-78