Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rcww-wv7r-4c78

Опубликовано: 17 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obtain sensitive information or execute arbitrary code.

A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obtain sensitive information or execute arbitrary code.

EPSS

Процентиль: 98%
0.65256
Средний

Связанные уязвимости

CVSS3: 8.8
nvd
около 6 лет назад

A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obtain sensitive information or execute arbitrary code.

EPSS

Процентиль: 98%
0.65256
Средний