Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qw4w-jhg4-f7wc

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Dreamweaver MX, when "Using Driver On Testing Server" or "Using DSN on Testing Server" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp.

Dreamweaver MX, when "Using Driver On Testing Server" or "Using DSN on Testing Server" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp.

EPSS

Процентиль: 74%
0.00824
Низкий

Связанные уязвимости

nvd
около 21 года назад

Dreamweaver MX, when "Using Driver On Testing Server" or "Using DSN on Testing Server" is selected, uploads the mmhttpdb.asp script to the web site but does not require authentication, which allows remote attackers to obtain sensitive information and possibly execute arbitrary SQL commands via a direct request to mmhttpdb.asp.

EPSS

Процентиль: 74%
0.00824
Низкий