Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qq9r-5mv8-w3px

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive containing a .php file that is able to execute OS commands. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.

Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive containing a .php file that is able to execute OS commands. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.

EPSS

Процентиль: 86%
0.02847
Низкий

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
nvd
около 5 лет назад

Jaws through 1.8.0 allows remote authenticated administrators to execute arbitrary code via crafted use of UploadTheme to upload a theme ZIP archive containing a .php file that is able to execute OS commands. NOTE: this is unrelated to the JAWS (aka Job Access With Speech) product.

EPSS

Процентиль: 86%
0.02847
Низкий

Дефекты

CWE-434