Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r23h-9vch-4xm4

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.

EPSS

Процентиль: 99%
0.84896
Высокий

Дефекты

CWE-829

Связанные уязвимости

CVSS3: 9.8
nvd
около 4 лет назад

The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.

EPSS

Процентиль: 99%
0.84896
Высокий

Дефекты

CWE-829