Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q66h-r8q8-x284

Опубликовано: 19 фев. 2022
Источник: github
Github: Не прошло ревью

Описание

This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.

This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.

EPSS

Процентиль: 57%
0.00353
Низкий

Дефекты

CWE-552

Связанные уязвимости

CVSS3: 9.8
ubuntu
почти 4 года назад

This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.

CVSS3: 9.8
nvd
почти 4 года назад

This affects the package cesanta/mongoose before 7.6. The unsafe handling of file names during upload using mg_http_upload() method may enable attackers to write files to arbitrary locations outside the designated target folder.

CVSS3: 9.8
debian
почти 4 года назад

This affects the package cesanta/mongoose before 7.6. The unsafe handl ...

EPSS

Процентиль: 57%
0.00353
Низкий

Дефекты

CWE-552