Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qh4h-cqrv-r6qp

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Directory traversal vulnerability in igallery.asp in Blue-Collar Productions i-Gallery 3.4 allows remote attackers to read arbitrary files via encoded backslash sequences in the d parameter, as demonstrated by a "%5c../../%5c" sequence.

Directory traversal vulnerability in igallery.asp in Blue-Collar Productions i-Gallery 3.4 allows remote attackers to read arbitrary files via encoded backslash sequences in the d parameter, as demonstrated by a "%5c../../%5c" sequence.

EPSS

Процентиль: 87%
0.03587
Низкий

Дефекты

CWE-22

Связанные уязвимости

nvd
больше 18 лет назад

Directory traversal vulnerability in igallery.asp in Blue-Collar Productions i-Gallery 3.4 allows remote attackers to read arbitrary files via encoded backslash sequences in the d parameter, as demonstrated by a "%5c../../%5c" sequence.

EPSS

Процентиль: 87%
0.03587
Низкий

Дефекты

CWE-22