Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qc5m-vfrf-pjxj

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Ideal Science Ideal BB 1.5.4a and earlier does not properly check file extensions before permitting an upload, which allows remote attackers to upload and execute an ASP script via a 0x00 character before the ".asp" portion of the filename.

Ideal Science Ideal BB 1.5.4a and earlier does not properly check file extensions before permitting an upload, which allows remote attackers to upload and execute an ASP script via a 0x00 character before the ".asp" portion of the filename.

EPSS

Процентиль: 75%
0.00909
Низкий

Связанные уязвимости

nvd
больше 19 лет назад

Ideal Science Ideal BB 1.5.4a and earlier does not properly check file extensions before permitting an upload, which allows remote attackers to upload and execute an ASP script via a 0x00 character before the ".asp" portion of the filename.

EPSS

Процентиль: 75%
0.00909
Низкий