Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qmp2-8m8m-8v95

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid, bd, ed, dt, and gtype parameters, a different vulnerability than CVE-2007-5112.

report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid, bd, ed, dt, and gtype parameters, a different vulnerability than CVE-2007-5112.

EPSS

Процентиль: 89%
0.04811
Низкий

Дефекты

CWE-287

Связанные уязвимости

nvd
больше 18 лет назад

report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid, bd, ed, dt, and gtype parameters, a different vulnerability than CVE-2007-5112.

EPSS

Процентиль: 89%
0.04811
Низкий

Дефекты

CWE-287