Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpg6-9qg9-qpwr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8

Описание

The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote attacker to get access to privileged information (e.g., /etc/passwd) via path traversal (relative path information in the file parameter of the corresponding POST request).

The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote attacker to get access to privileged information (e.g., /etc/passwd) via path traversal (relative path information in the file parameter of the corresponding POST request).

EPSS

Процентиль: 71%
0.00696
Низкий

8 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 8
nvd
больше 6 лет назад

The diagnostics web interface in the Yeahlink Ultra-elegant IP Phone SIP-T41P (firmware 66.83.0.35) does not validate (escape) the path information (path traversal), which allows an authenticated remote attacker to get access to privileged information (e.g., /etc/passwd) via path traversal (relative path information in the file parameter of the corresponding POST request).

EPSS

Процентиль: 71%
0.00696
Низкий

8 High

CVSS3

Дефекты

CWE-22